CVE-2026-46687EPSS p35.8%
CVE-2026-46687CVE-2026-46687
Description
Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls include View::getView($template), allowing an authenticated author to include an arbitrary local .php file when an article is viewed. No fixed version is currently identified.
Scoring
| EPSS | 0.44% probability of exploitation · percentile 35.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-17 |