CVE-2026-46686
NONE—CVSS v3
—CVSS v2
0.32%
EPSS (exploit probability)
CWE-79CWE
Description
Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php is processed with addslashes but not HTML-escaped before being rendered into the value attribute in admin/views/user.php, allowing reflected cross-site scripting in an administrator's backend session. No fixed version is currently identified.
Affected routers (0)
No routers currently mapped to this CVE in our database.