VYPR

Emlog

by Emlog

Source repositories

CVEs (105)

  • CVE-2025-61930HigOct 10, 2025
    risk 0.53cvss 8.1epss 0.00

    Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change endpoint. An attacker can trick a logged‑in administrator into submitting a crafted POST request to change the…

  • CVE-2025-53923HigJul 16, 2025
    risk 0.53cvss 8.2epss 0.00

    Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject…

  • CVE-2026-21433HigJan 2, 2026
    risk 0.50cvss 7.7epss 0.00

    Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF via uploaded SVG files. An attacker can upload a crafted SVG to http[:]//emblog/admin/media[.]php which contains external resource…

  • CVE-2020-19028HigJun 5, 2023
    risk 0.49cvss 7.5epss 0.01

    *File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php function.

  • CVE-2026-39276HigMay 29, 2026
    risk 0.47cvss 7.2epss 0.01

    The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default…

  • CVE-2026-34607HigApr 3, 2026
    risk 0.47cvss 7.2epss 0.01

    Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting ZIP archives (plugin/template uploads, backup imports), the function calls…

  • CVE-2025-44139HigAug 1, 2025
    risk 0.47cvss 7.2epss 0.01

    Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip

  • CVE-2025-5119HigMay 23, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2025-25823HigFeb 26, 2025
    risk 0.47cvss 7.3epss 0.00

    A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php.

  • CVE-2023-41623HigDec 12, 2023
    risk 0.47cvss 7.2epss 0.01

    Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php.

  • CVE-2023-39121HigAug 3, 2023
    risk 0.47cvss 7.2epss 0.03

    emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

  • CVE-2022-42189HigOct 21, 2022
    risk 0.47cvss 7.2epss 0.01

    Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.

  • CVE-2020-21654HigOct 6, 2021
    risk 0.47cvss 7.2epss 0.01

    emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.

  • CVE-2020-21013HigOct 1, 2021
    risk 0.47cvss 7.2epss 0.01

    emlog v6.0.0 contains a SQL injection via /admin/comment.php.

  • CVE-2025-25825HigFeb 26, 2025
    risk 0.46cvss 7.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.

  • CVE-2025-53924MedJul 16, 2025
    risk 0.45cvss 6.9epss 0.00

    Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code…

  • CVE-2026-73847MedAug 14, 2026
    risk 0.44cvss 6.8epss

    Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently…

  • CVE-2025-25827MedFeb 26, 2025
    risk 0.44cvss 6.8epss 0.00

    A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted URL.

  • CVE-2026-34788MedApr 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag_model.php at line 168. The updateTagName() function directly interpolates user input into the SQL query string without using parameterized…

  • CVE-2026-34787MedApr 3, 2026
    risk 0.42cvss 6.5epss 0.01

    Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php at line 80. The $plugin parameter from the GET request is directly used in a require_once path without proper sanitization. If the…

Page 2 of 6