CVE-2026-31954

Published Mar 11, 2026

Last updated 5 days ago

Overview

Description
Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.
Source
security-advisories@github.com
NVD status
Analyzed
Products
emlog

Risk scores

CVSS 3.1

Type
Primary
Base score
7.3
Impact score
5.2
Exploitability score
2.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-352

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.