VYPR

Emlog

by Emlog

Source repositories

CVEs (105)

  • CVE-2026-34228MedApr 3, 2026
    risk 0.35cvss 6.5epss 0.00

    Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQL and ZIP URLs via GET parameters. The server first downloads and executes the SQL file, then downloads the ZIP file and extracts it directly into the web root…

  • CVE-2026-21432MedJan 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can lead to account takeover, including takeover of admin accounts. As of time of publication, no known patched versions are available.

  • CVE-2026-21431MedJan 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `Resource media library ` function while publishing an article. As of time of publication, no known patched versions are available.

  • CVE-2025-61599MedOct 3, 2025
    risk 0.35cvss 5.4epss 0.00

    Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitter"feature of EMLOG Pro 2.5.21 and below. An authenticated user with privileges to post a "Twitter" message can inject arbitrary JavaScript code. The malicious…

  • CVE-2025-53925MedJul 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is…

  • CVE-2024-50655MedNov 15, 2024
    risk 0.35cvss 5.4epss 0.00

    emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript code in published articles.

  • CVE-2023-43267MedOct 2, 2023
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title field.

  • CVE-2023-30338MedApr 27, 2023
    risk 0.35cvss 5.4epss 0.00

    Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Article Title or Article Summary parameters.

  • CVE-2021-40610MedJun 9, 2022
    risk 0.35cvss 5.4epss 0.00

    Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.

  • CVE-2026-34229MedApr 3, 2026
    risk 0.33cvss 6.1epss 0.00

    Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment module via URI scheme validation bypass. This issue has been patched in version 2.6.8.

  • CVE-2025-25818MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the postStrVar function at article_save.php.

  • CVE-2025-9296MedAug 21, 2025
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The…

  • CVE-2025-47786MedMay 15, 2025
    risk 0.31cvss 4.8epss 0.00

    Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that allows any registered user to construct malicious JavaScript, inducing all website users to click. In `/admin/comment.php`, the parameter `perpage_num` is not…

  • CVE-2024-5043MedMay 17, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown functionality of the file admin/setting.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the…

  • CVE-2022-43372MedNov 3, 2022
    risk 0.31cvss 4.8epss 0.00

    Emlog Pro v1.7.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /admin/store.php.

  • CVE-2022-23872MedJan 31, 2022
    risk 0.31cvss 4.8epss 0.01

    Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/configure.php via the parameter footer_info.

  • CVE-2026-21429MedJan 2, 2026
    risk 0.28cvss 4.3epss 0.00

    Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable to edit or delete their articles after publishing them. As of time of publication, no known patched versions are available.

  • CVE-2024-12846MedDec 21, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is some unknown functionality of the file /admin/link.php. The manipulation of the argument siteurl/icon leads to cross site scripting. The attack may be…

  • CVE-2024-12844MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.1. Affected is an unknown function of the file /admin/store.php. The manipulation of the argument tag leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2024-12843MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Emlog Pro up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the file /admin/plugin.php. The manipulation of the argument filter leads to cross site scripting. The attack may be initiated remotely. The…

Page 4 of 6