Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator reviews or previews the submitted article in the backend, the malicious script executes in the admin's browser session, allowing the attacker to perform administrative actions such as creating a backdoor administrator account.
CVE-2026-52520
NONE
Updated Aug 04, 2026
PHP
CVE Details
CVE ID
CVE-2026-52520
Published Date
Aug 04, 2026
Vendor
PHP
Severity
NONE
Impact
Minimal impact
Source
View Advisory