CVE-2026-53756Medium· 4.9▾ TwilightPoC availableEmlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filt…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 27 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filtering. The vulnerability is reachable through the auth cookie validation path, where $username is extracted from the cookie and passed unfiltered into SQL — guarded only by an HMAC signature that requires AUTH_KEY to forge. This issue has been patched in version 2.6.16.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53758High· 8.7Emlog is an open source website building system
CVE-2026-73848Medium· 6.9Emlog is an open source website building system
CVE-2026-53757Medium· 6.9Emlog is an open source website building system
CVE-2017-18362Critical· 9.8ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database
CVE-2019-7481High· 7.5Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources
CVE-2023-4548Medium· 6.3A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3