CVE-2026-31954
Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.
Vendor
Product
CWE
Yayın Tarihi
2026-03-11 20:16:16
Güncelleme
2026-03-17 21:05:16
Source Identifier
security-advisories@github.com
KEV Date Added
-