Emlog
by Emlog
Source repositories
CVEs (109)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73847 | Med | 0.44 | 6.8 | 0.00 | Aug 14, 2026 | Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently… | ||
| CVE-2025-25827 | Med | 0.44 | 6.8 | 0.00 | Feb 26, 2025 | A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted URL. | ||
| CVE-2026-34788 | Med | 0.42 | 6.5 | 0.00 | Apr 3, 2026 | Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag_model.php at line 168. The updateTagName() function directly interpolates user input into the SQL query string without using parameterized… | ||
| CVE-2026-34787 | Med | 0.42 | 6.5 | 0.01 | Apr 3, 2026 | Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php at line 80. The $plugin parameter from the GET request is directly used in a require_once path without proper sanitization. If the… | ||
| CVE-2024-31612 | Med | 0.42 | 6.5 | 0.00 | Jun 10, 2024 | Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator information. | ||
| CVE-2023-37049 | Med | 0.42 | 6.5 | 0.01 | Jul 26, 2023 | emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php. | ||
| CVE-2020-21014 | Med | 0.42 | 6.5 | 0.01 | Oct 1, 2021 | emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php. | ||
| CVE-2019-17073 | Med | 0.42 | 6.5 | 0.02 | Oct 1, 2019 | emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal. | ||
| CVE-2025-29405 | Med | 0.41 | 6.3 | 0.00 | Mar 19, 2025 | An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2024-46540 | Med | 0.41 | 6.3 | 0.01 | Sep 30, 2024 | A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges. | ||
| CVE-2024-33752 | Med | 0.41 | 6.3 | 0.05 | May 6, 2024 | An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit a special request to upload a malicious file to execute arbitrary code. | ||
| CVE-2025-60448 | Med | 0.40 | 6.1 | 0.00 | Oct 3, 2025 | A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code… | ||
| CVE-2025-53926 | Med | 0.40 | 6.1 | 0.00 | Jul 16, 2025 | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requires the victim to send… | ||
| CVE-2024-31013 | Med | 0.40 | 6.1 | 0.00 | Apr 3, 2024 | Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in footer_info parameter. | ||
| CVE-2024-25381 | Med | 0.40 | 6.1 | 0.00 | Feb 21, 2024 | There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content. | ||
| CVE-2023-41619 | Med | 0.40 | 6.1 | 0.00 | Jan 16, 2024 | Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write. | ||
| CVE-2023-41618 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin/article.php?active_savedraft. | ||
| CVE-2023-41621 | Med | 0.40 | 6.1 | 0.01 | Dec 13, 2023 | A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php. | ||
| CVE-2023-41597 | Med | 0.40 | 6.1 | 0.01 | Nov 15, 2023 | EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t. | ||
| CVE-2020-18194 | Med | 0.40 | 6.1 | 0.02 | May 17, 2021 | Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post. |
- risk 0.44cvss 6.8epss 0.00
Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently…
- risk 0.44cvss 6.8epss 0.00
A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted URL.
- risk 0.42cvss 6.5epss 0.00
Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag_model.php at line 168. The updateTagName() function directly interpolates user input into the SQL query string without using parameterized…
- risk 0.42cvss 6.5epss 0.01
Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php at line 80. The $plugin parameter from the GET request is directly used in a require_once path without proper sanitization. If the…
- risk 0.42cvss 6.5epss 0.00
Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator information.
- risk 0.42cvss 6.5epss 0.01
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
- risk 0.42cvss 6.5epss 0.01
emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.
- risk 0.42cvss 6.5epss 0.02
emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
- risk 0.41cvss 6.3epss 0.00
An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.41cvss 6.3epss 0.01
A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.
- risk 0.41cvss 6.3epss 0.05
An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit a special request to upload a malicious file to execute arbitrary code.
- risk 0.40cvss 6.1epss 0.00
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code…
- risk 0.40cvss 6.1epss 0.00
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requires the victim to send…
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in footer_info parameter.
- risk 0.40cvss 6.1epss 0.00
There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.
- risk 0.40cvss 6.1epss 0.00
Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.
- risk 0.40cvss 6.1epss 0.00
Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin/article.php?active_savedraft.
- risk 0.40cvss 6.1epss 0.01
A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.
- risk 0.40cvss 6.1epss 0.01
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
- risk 0.40cvss 6.1epss 0.02
Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post.
Page 3 of 6