Vulnerability Description
Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.
CVSS Score
NONE
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emlog | Emlog | <= 2.6.6 |
Related Weaknesses (CWE)
References
- https://github.com/emlog/emlog/security/advisories/GHSA-xc26-93qj-rcrwExploitVendor Advisory
FAQ
What is CVE-2026-31954?
CVE-2026-31954 is a vulnerability with a CVSS score of 0.0 (NONE). Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.
How severe is CVE-2026-31954?
CVE-2026-31954 has been rated NONE with a CVSS base score of 0.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-31954?
Check the references section above for vendor advisories and patch information. Affected products include: Emlog Emlog.