Cross-site scripting in Emlog Pro - CVE-2026-52520
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the browsers of users who view a crafted article.
The vulnerability exists due to cross-site scripting in the article publishing module and Parsedown output handling when rendering article content supplied through the content field. A remote user can publish an article containing malicious HTML or JavaScript to execute arbitrary JavaScript in the browsers of users who view a crafted article.
User interaction is required because a victim must view the malicious article.