PT-2026-24803 · Emlog+1 · Emlog

·

CVE-2026-31954

·

Published

2026-03-11

·

Updated

2026-03-11

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emlog versions 2.6.6 and earlier
Description Emlog is an open source website building system. The delete async action lacks a call to LoginAuth::checkToken(), which allows for Cross-Site Request Forgery (CSRF) attacks. The vulnerable action is delete async.
Recommendations Versions prior to 2.6.6 should be updated.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31954
GHSA-XC26-93QJ-RCRW

Affected Products

Emlog