Vulnerability  ·  2026-08-16

Emlog CMS: SQL injection in AI Assistant backend (ai.php) via queryDatabase

VulnerabilityHigh impactGlobalCVE-2026-73850
A SQL injection vulnerability exists in Emlog's built-in AI Assistant backend logic, allowing database manipulation via crafted input to the AI feature's query path. CVSS 8.6 (High).
Shows that bolting AI-assistant features onto legacy CMS codebases can reintroduce classic injection vulnerabilities within the new AI-specific code path; narrow blast radius limited to Emlog's install base.
The queryDatabase function inside the AI Assistant module (ai.php) fails to sanitize input, allowing SQL injection through the CMS's AI-assistant-facing endpoint.
Emlog ≤ 2.6.20
Upgrade Emlog past the fixed version referenced in GHSA-jffg-rpvp-2qx7.
GitHub Security Advisory GHSA-jffg-rpvp-2qx7
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →