CVE-2026-73848
Dashboard / Vulnerabilities / CVE-2026-73848
Summary: Emlog: Stored XSS via Tag Name in Article Editor
Details: Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslashes() function does not escape HTML entities, so ' is stored as-is. When the browser renders the page, it decodes ' back to a literal single quote before evaluating the JavaScript, breaking out of the string and executing arbitrary code. At time of publication, there are no publicly known patches.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73848.json, https://github.com/emlog/emlog/security/advisories/GHSA-fv6h-wr92-v4pj, https://nvd.nist.gov/vuln/detail/CVE-2026-73848
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
