Emlog
by Emlog
Source repositories
CVEs (109)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47785 | Hig | 0.54 | 8.3 | 0.01 | May 15, 2025 | Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this… | ||
| CVE-2025-61930 | Hig | 0.53 | 8.1 | 0.00 | Oct 10, 2025 | Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change endpoint. An attacker can trick a logged‑in administrator into submitting a crafted POST request to change the… | ||
| CVE-2025-53923 | Hig | 0.53 | 8.2 | 0.00 | Jul 16, 2025 | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject… | ||
| CVE-2026-21433 | Hig | 0.50 | 7.7 | 0.00 | Jan 2, 2026 | Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF via uploaded SVG files. An attacker can upload a crafted SVG to http[:]//emblog/admin/media[.]php which contains external resource… | ||
| CVE-2020-19028 | Hig | 0.49 | 7.5 | 0.01 | Jun 5, 2023 | *File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php function. | ||
| CVE-2026-67598 | Hig | 0.48 | 7.4 | 0.00 | Aug 3, 2026 | Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as… | ||
| CVE-2026-39276 | Hig | 0.47 | 7.2 | 0.01 | May 29, 2026 | The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default… | ||
| CVE-2026-34607 | Hig | 0.47 | 7.2 | 0.01 | Apr 3, 2026 | Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting ZIP archives (plugin/template uploads, backup imports), the function calls… | ||
| CVE-2025-44139 | Hig | 0.47 | 7.2 | 0.01 | Aug 1, 2025 | Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip | ||
| CVE-2025-5119 | Hig | 0.47 | 7.3 | 0.01 | May 23, 2025 | A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be initiated remotely. The… | ||
| CVE-2025-25823 | Hig | 0.47 | 7.3 | 0.00 | Feb 26, 2025 | A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php. | ||
| CVE-2023-41623 | Hig | 0.47 | 7.2 | 0.01 | Dec 12, 2023 | Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php. | ||
| CVE-2023-39121 | Hig | 0.47 | 7.2 | 0.03 | Aug 3, 2023 | emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php. | ||
| CVE-2022-42189 | Hig | 0.47 | 7.2 | 0.02 | Oct 21, 2022 | Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability. | ||
| CVE-2020-21654 | Hig | 0.47 | 7.2 | 0.01 | Oct 6, 2021 | emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file. | ||
| CVE-2020-21013 | Hig | 0.47 | 7.2 | 0.01 | Oct 1, 2021 | emlog v6.0.0 contains a SQL injection via /admin/comment.php. | ||
| CVE-2025-25825 | Hig | 0.46 | 7.1 | 0.00 | Feb 26, 2025 | A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section. | ||
| CVE-2026-73848 | Med | 0.45 | — | 0.00 | Sep 4, 2026 | Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslashes() function does not escape HTML… | ||
| CVE-2026-53757 | Med | 0.45 | — | 0.00 | Sep 4, 2026 | Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory structure is checked. An… | ||
| CVE-2025-53924 | Med | 0.45 | 6.9 | 0.00 | Jul 16, 2025 | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code… |
- risk 0.54cvss 8.3epss 0.01
Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this…
- risk 0.53cvss 8.1epss 0.00
Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change endpoint. An attacker can trick a logged‑in administrator into submitting a crafted POST request to change the…
- risk 0.53cvss 8.2epss 0.00
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject…
- risk 0.50cvss 7.7epss 0.00
Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF via uploaded SVG files. An attacker can upload a crafted SVG to http[:]//emblog/admin/media[.]php which contains external resource…
- risk 0.49cvss 7.5epss 0.01
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php function.
- risk 0.48cvss 7.4epss 0.00
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as…
- risk 0.47cvss 7.2epss 0.01
The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default…
- risk 0.47cvss 7.2epss 0.01
Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting ZIP archives (plugin/template uploads, backup imports), the function calls…
- risk 0.47cvss 7.2epss 0.01
Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip
- risk 0.47cvss 7.3epss 0.01
A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be initiated remotely. The…
- risk 0.47cvss 7.3epss 0.00
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php.
- risk 0.47cvss 7.2epss 0.01
Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php.
- risk 0.47cvss 7.2epss 0.03
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
- risk 0.47cvss 7.2epss 0.02
Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.
- risk 0.47cvss 7.2epss 0.01
emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.
- risk 0.47cvss 7.2epss 0.01
emlog v6.0.0 contains a SQL injection via /admin/comment.php.
- risk 0.46cvss 7.1epss 0.00
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.
- risk 0.45cvss —epss 0.00
Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslashes() function does not escape HTML…
- risk 0.45cvss —epss 0.00
Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory structure is checked. An…
- risk 0.45cvss 6.9epss 0.00
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code…
Page 2 of 6