Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53758— Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized

Quick assessment

Affected
emlog emlog
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Emlog 是一款开源的网站建设系统。在 2.6.29 版本及更早的版本中,文章内容通过 Parsedown 进行处理,但未启用安全模式(safe mode),这意味着嵌入在 Markdown 中的原始 HTML(包括 标签)未经转义处理就直接通过。输出结果在没有额外净化(sanitization)的情况下被渲染,导致所有站点访问者都能看到存储型跨站脚本攻击(Stored XSS)。截至公告发布时,尚无已知的公开补丁。

CVSS 8.7 · High EPSS 0.02% · P5

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
emlog emlog <= 2.6.29 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53758

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized
Source: CVE Program / CVE List V5
Vulnerability Description
Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML including <script> tags embedded in Markdown is passed through unescaped. The output is rendered with no additional sanitization, resulting in stored XSS visible to all site visitors. At time of publication, there are no publicly known patches.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
emlog emlog <= 2.6.29 -

II. Public POCs for CVE-2026-53758

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53758

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53758 (1)

Same Patch Batch · emlog · 2026-09-04 · 4 CVEs total

CVE-2026-53757 6.9 MEDIUM Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE
CVE-2026-73848 6.9 MEDIUM Emlog: Stored XSS via Tag Name in Article Editor
CVE-2026-53756 4.9 MEDIUM Emlog Blind SQL Injection via Authentication Cookie

IV. Related Vulnerabilities

V. Comments for CVE-2026-53758

No comments yet


Leave a comment