10
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially leading to complete database compromise, data theft, or system destruction. This issue has been patched in version 2.6.11.
AI Analysis
SQL injection vulnerability in Emlog's log_model.php within addLog() and updateLog() functions, allowing attackers to execute arbitrary SQL commands, potentially leading to database compromise, data theft, or system destruction.
Basic Information
ID
CVE-2026-42287
Source
GitHub_M
Published
May 8, 2026 at 21:51
Affected Product
Vendor
emlog
Product
emlog
Version
< 2.6.11
Affected Versions
emlog emlog < 2.6.11
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Emlog
Product
Emlog
Version
< 2.6.11