CVE 10 CRITICAL

Emlog: SQL Injection Vulnerability in log_model.php within addLog() and updateLog() Functions_CVE-2026-42287

10 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially leading to complete database compromise, data theft, or system destruction. This issue has been patched in version 2.6.11.

AI Analysis

SQL injection vulnerability in Emlog's log_model.php within addLog() and updateLog() functions, allowing attackers to execute arbitrary SQL commands, potentially leading to database compromise, data theft, or system destruction.

Basic Information

ID CVE-2026-42287
Source GitHub_M
Published May 8, 2026 at 21:51

Affected Product

Vendor emlog
Product emlog
Version < 2.6.11
Affected Versions emlog emlog < 2.6.11

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor Emlog
Product Emlog
Version < 2.6.11

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.