Junglewise Threat Intelligence

CVE-2026-34788: Emlog SQL injection in tag_model updateTagName

CVE-2026-34788 · Severity: medium · CVSS 6.5 · Published 2026-04-03

Technologies: Emlog. Vendors: Emlog.

Executive brief

Emlog is an open-source website building and content management system. A security flaw in the tag management system allows an administrative user to execute unauthorized database commands. This could lead to the theft of sensitive information or the modification of website content, though it requires high-level access to exploit.

Technical details

A SQL injection vulnerability exists in the updateTagName() function within include/model/tag_model.php. The root cause is the direct interpolation of user-supplied variables ($tagName, $kw, $title, and $description) into a SQL UPDATE statement without proper escaping or parameterized queries. While the application uses addslashes(), this is insufficient to prevent injection in certain database configurations. An authenticated attacker with administrative privileges can exploit this via a network request to modify tag data, potentially gaining full read/write access to the database. As of the advisory date, no official patch has been released.

Affected products

  • Emlog Emlog <= 2.6.2

Timeline

  • 2026-03-31: advisory: GitHub Security Advisory published
  • 2026-04-03: disclosed: NVD publication date

References

Related threats