CVE-2026-46686
emlog
Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php is processed with addslashes but not HTML-escaped before being rendered into the value attribute in admin/views/user.php, allowing reflected cross-site scripting in an administrator's backend session. No fixed version is currently identified.
- CVSS
- 8.5
- EPSS
- 0.32% 24.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.17