Emlog 是一款开源的网站建设系统。在 2.6.29 版本及更早的版本中,文章内容通过 Parsedown 进行处理,但未启用安全模式(safe mode),这意味着嵌入在 Markdown 中的原始 HTML(包括 标签)未经转义处理就直接通过。输出结果在没有额外净化(sanitization)的情况下被渲染,导致所有站点访问者都能看到存储型跨站脚本攻击(Stored XSS)。截至公告发布时,尚无已知的公开补丁。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53757 | 6.9 MEDIUM | Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE |
| CVE-2026-73848 | 6.9 MEDIUM | Emlog: Stored XSS via Tag Name in Article Editor |
| CVE-2026-53756 | 4.9 MEDIUM | Emlog Blind SQL Injection via Authentication Cookie |
No comments yet