VYPR

Emlog

by Emlog

Source repositories

CVEs (105)

  • CVE-2025-61597HigOct 3, 2025
    risk 0.00cvss 7.6epss 0.00

    Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored cross‑site scripting (XSS) via the mail template settings. Once a malicious payload is saved, any subsequent visit to the settings page in an authenticated…

  • CVE-2025-47787CriMay 15, 2025
    risk 0.00cvss 9.8epss 0.01

    Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP plugin files. This…

  • CVE-2025-47784CriMay 15, 2025
    risk 0.00cvss 9.8epss 0.00

    Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deserialization to fail and return…

  • CVE-2022-3968LowNov 13, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/article_save.php. The manipulation of the argument tag leads to cross site scripting. The attack can be launched remotely. The name…

  • CVE-2021-44584MedJan 6, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in emlog version <= pro-1.0.7 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

Page 6 of 6