PT-2026-86177 · Emlog+1 · Emlog

CVE-2026-73848

·

Published

2026-09-04

·

Updated

2026-09-11

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVE-2026-73848: XSS in emlog ≤2.6.29 via unescaped tag names in article editor. Attacker executes arbitrary JS via crafted tag—full account takeover risk. CVSS N/A. UNPATCHED. Update or restrict editor access immediately. Details: https://t.co/utDcwWYnT1 #cybersecurit #valtersit #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #china #france #germany #docker #kali

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73848
GHSA-FV6H-WR92-V4PJ

Affected Products

Emlog