VYPR

Vendor CVEs

Emlog

All CVEs

109 total · sorted by risk
  • CVE-2026-31954NonMar 11, 2026
    risk 0.00cvss 0.0epss 0.00

    Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.

  • CVE-2026-22799HigJan 12, 2026
    risk 0.00cvss 8.8epss 0.01

    Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allowing authenticated attackers…

  • CVE-2025-62717CriOct 24, 2025
    risk 0.00cvss 9.1epss 0.00

    Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been…

  • CVE-2025-61769MedOct 6, 2025
    risk 0.00cvss 6.1epss 0.00

    Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is…

  • CVE-2025-61597HigOct 3, 2025
    risk 0.00cvss 7.6epss 0.00

    Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored cross‑site scripting (XSS) via the mail template settings. Once a malicious payload is saved, any subsequent visit to the settings page in an authenticated…

  • CVE-2025-47787CriMay 15, 2025
    risk 0.00cvss 9.8epss 0.01

    Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP plugin files. This…

  • CVE-2025-47784CriMay 15, 2025
    risk 0.00cvss 9.8epss 0.00

    Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deserialization to fail and return…

  • CVE-2022-3968LowNov 13, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/article_save.php. The manipulation of the argument tag leads to cross site scripting. The attack can be launched remotely. The name…

  • CVE-2021-44584MedJan 6, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in emlog version <= pro-1.0.7 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

Page 3 of 3