Cross-site scripting in Emlog Pro - CVE-2026-73848

 

Cross-site scripting in Emlog Pro - CVE-2026-73848

Published: August 15, 2026


Vulnerability identifier: #VU142819
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-73848
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in an administrator\'s browser.

The vulnerability exists due to cross-site scripting in the article editor tag rendering in admin/views/article_write.php when rendering tag names inside a javascript: href attribute. A remote user can create a crafted tag name and induce an administrator to click the poisoned tag to execute arbitrary JavaScript in an administrator\'s browser.

User interaction is required because an administrator must open the article editor, expand the tag list, and click the crafted tag.


Affected software

Emlog Pro

How to mitigate CVE-2026-73848

Install security update from vendor's website.

Emlog Pro - update to 2.5.1

External References

Related Security Bulletins