VYPR

Emlog

by Emlog

Source repositories

CVEs (105)

  • CVE-2024-12842MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/user.php. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit…

  • CVE-2024-12841MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part of the file /admin/tag.php. The manipulation of the argument keyword leads to cross site scripting. It is possible to initiate the attack remotely. The exploit…

  • CVE-2020-21321MedSep 15, 2021
    risk 0.28cvss 4.3epss 0.01

    emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.

  • CVE-2024-5044LowMay 17, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in Emlog Pro 2.3.4. It has been classified as problematic. This affects an unknown part of the component Cookie Handler. The manipulation of the argument AuthCookie leads to improper authentication. It is possible to initiate the attack remotely. The…

  • CVE-2025-5886LowJun 9, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin/article.php. The manipulation of the argument active_post leads to cross site scripting. The attack may be initiated remotely. The exploit…

  • CVE-2024-13140LowJan 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.3. Affected is an unknown function of the file /admin/article.php?action=upload_cover of the component Cover Upload Handler. The manipulation of the argument image leads to cross site scripting. It…

  • CVE-2024-13135LowJan 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in Emlog Pro 2.4.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/twitter.php of the component Subpage Handler. The manipulation leads to cross site scripting. The attack can be launched…

  • CVE-2024-13132LowJan 5, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in Emlog Pro up to 2.4.3. This vulnerability affects unknown code of the file /admin/article.php of the component Subpage Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The…

  • CVE-2024-12845LowDec 20, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unknown functionality in the library /include/lib/common.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched…

  • CVE-2022-1526LowApr 29, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The manipulation with the input leads to cross site scripting. It is possible to initiate the attack…

  • CVE-2024-3763LowApr 14, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in Emlog Pro 2.2.10. It has been rated as problematic. This issue affects some unknown processing of the file /admin/tag.php of the component Post Tag Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The…

  • CVE-2024-3762LowApr 14, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in Emlog Pro 2.2.10. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/twitter.php of the component Whisper Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The…

  • CVE-2026-67598HigAug 3, 2026
    risk 0.00cvss 7.4epss 0.00

    Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as…

  • CVE-2026-46687HigJul 16, 2026
    risk 0.00cvss epss 0.00

    Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls include…

  • CVE-2026-46686HigJul 16, 2026
    risk 0.00cvss epss 0.00

    Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php is processed with addslashes but not HTML-escaped before being rendered into the value attribute in admin/views/user.php, allowing…

  • CVE-2026-41517NonMay 8, 2026
    risk 0.00cvss epss 0.00

    Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. This issue has been patched in…

  • CVE-2026-31954NonMar 11, 2026
    risk 0.00cvss 0.0epss 0.00

    Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.

  • CVE-2026-22799HigJan 12, 2026
    risk 0.00cvss 8.8epss 0.01

    Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allowing authenticated attackers…

  • CVE-2025-62717CriOct 24, 2025
    risk 0.00cvss 9.1epss 0.00

    Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been…

  • CVE-2025-61769MedOct 6, 2025
    risk 0.00cvss 6.1epss 0.00

    Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is…

Page 5 of 6