VYPR

Emlog

by Emlog

Source repositories

CVEs (105)

  • CVE-2024-31612MedJun 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator information.

  • CVE-2023-37049MedJul 26, 2023
    risk 0.42cvss 6.5epss 0.01

    emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.

  • CVE-2020-21014MedOct 1, 2021
    risk 0.42cvss 6.5epss 0.01

    emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.

  • CVE-2019-17073MedOct 1, 2019
    risk 0.42cvss 6.5epss 0.02

    emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.

  • CVE-2025-29405MedMar 19, 2025
    risk 0.41cvss 6.3epss 0.00

    An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-46540MedSep 30, 2024
    risk 0.41cvss 6.3epss 0.01

    A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.

  • CVE-2024-33752MedMay 6, 2024
    risk 0.41cvss 6.3epss 0.05

    An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit a special request to upload a malicious file to execute arbitrary code.

  • CVE-2025-60448MedOct 3, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code…

  • CVE-2025-53926MedJul 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requires the victim to send…

  • CVE-2024-31013MedApr 3, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in footer_info parameter.

  • CVE-2024-25381MedFeb 21, 2024
    risk 0.40cvss 6.1epss 0.00

    There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.

  • CVE-2023-41619MedJan 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.

  • CVE-2023-41618MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin/article.php?active_savedraft.

  • CVE-2023-41621MedDec 13, 2023
    risk 0.40cvss 6.1epss 0.01

    A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.

  • CVE-2023-41597MedNov 15, 2023
    risk 0.40cvss 6.1epss 0.01

    EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

  • CVE-2020-18194MedMay 17, 2021
    risk 0.40cvss 6.1epss 0.02

    Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post.

  • CVE-2021-30227MedApr 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0.

  • CVE-2025-60447MedOct 3, 2025
    risk 0.38cvss 5.9epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/setting.php?action=mail, which allows administrators to input HTML code that is not properly…

  • CVE-2021-3293MedFeb 8, 2021
    risk 0.36cvss 5.3epss 0.21

    emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.

  • CVE-2026-52520MedAug 3, 2026
    risk 0.35cvss 5.4epss 0.00

    Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator reviews or previews the…

Page 3 of 6