VYPR

Emlog V2.6.9 Vulnerability Report

by Ling12138 Sg

Source repositories

CVEs (1)

  • CVE-2026-39276HigMay 29, 2026
    risk 0.47cvss 7.2epss

    The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default…