VYPR
Unrated severityNVD Advisory· Published Oct 3, 2025· Updated Oct 3, 2025

CVE-2025-60448

CVE-2025-60448

Description

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed.

Affected products

2
  • Emlog/Prodescription
  • Emlog/Emlogllm-fuzzy
    Range: =2.5.19

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.