PT-2026-30268 · Emlog · Emlog
Published
2026-04-03
·
Updated
2026-04-03
·
CVE-2026-34788
CVSS v3.1
6.5
Medium
| AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag model.php at line 168. The updateTagName() function directly interpolates user input into the SQL query string without using parameterized queries or proper escaping ($this->db->escape string()), making it vulnerable to SQL injection attacks. At time of publication, there are no publicly available patches.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emlog