📦 Emlog

by Emlog

🔍 What is Emlog?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21430

CRITICAL CVSS 9.3 Jan 2, 2026

CVE-2026-21430 is a CSRF vulnerability in Emlog's article creation functionality that allows attackers to force users to post malicious articles. When combined with stored XSS, this can lead to accoun...

CVE-2025-61318

CRITICAL CVSS 9.1 Dec 8, 2025

Emlog Pro 2.5.20 contains an arbitrary file deletion vulnerability in admin/template.php and admin/plugin.php components. Attackers can exploit directory traversal to delete critical system files with...

CVE-2025-62717

CRITICAL CVSS 9.1 Oct 24, 2025

Emlog Pro 2.5.23 has a session verification code error that allows attackers to reuse email verification codes. This authentication bypass vulnerability affects all Emlog Pro installations using email...

CVE-2025-47787

CRITICAL CVSS 9.8 May 15, 2025

Emlog Pro versions before 2.5.10 contain a critical file upload vulnerability in the store.php component that fails to properly validate remotely downloaded ZIP plugin files. This allows attackers to ...

CVE-2025-47784

CRITICAL CVSS 9.8 May 15, 2025

Emlog versions 2.5.13 and prior contain a deserialization vulnerability where a user can craft a malicious nickname to cause deserialization failure. This could potentially lead to remote code executi...

CVE-2025-30372

CRITICAL CVSS 9.8 Mar 28, 2025

Emlog Pro versions 2.5.7 and 2.5.8 contain an SQL injection vulnerability in search_controller.php due to improper input sanitization. Attackers can bypass addslashes protection using URL double encod...

CVE-2023-44973

CRITICAL CVSS 9.8 Oct 3, 2023

This vulnerability allows attackers to upload arbitrary PHP files to Emlog Pro's template directory, leading to remote code execution. It affects Emlog Pro v2.2.0 installations with the vulnerable com...

CVE-2023-43291

CRITICAL CVSS 9.8 Sep 27, 2023

CVE-2023-43291 is a critical deserialization vulnerability in emlog pro CMS that allows remote attackers to execute arbitrary code on affected systems. Attackers can exploit this via the cache.php com...

CVE-2021-40883

CRITICAL CVSS 9.8 Dec 14, 2021

This vulnerability allows unauthenticated attackers to upload malicious PHP files through the plugin upload functionality in emlog, leading to remote code execution. It affects all emlog 5.3.1 install...

CVE-2020-21585

CRITICAL CVSS 9.8 Apr 2, 2021

CVE-2020-21585 is a critical vulnerability in emlog v6.0.0 that allows authenticated users to upload malicious PHP webshells via the zip plugin module. This affects all emlog v6.0.0 installations with...

CVE-2026-21433

HIGH CVSS 7.7 Jan 2, 2026

Emlog versions up to 2.5.19 are vulnerable to server-side request forgery (SSRF) via malicious SVG file uploads. Attackers can upload crafted SVG files that force the server to make HTTP requests to a...

CVE-2025-61597

HIGH CVSS 7.6 Oct 3, 2025

Emlog versions 2.5.21 and below contain a stored cross-site scripting (XSS) vulnerability in mail template settings. An attacker with admin access can inject malicious JavaScript that executes when ot...

CVE-2025-53923

HIGH CVSS 8.2 Jul 16, 2025

Emlog website building system contains a cross-site scripting (XSS) vulnerability in the keyword parameter that allows attackers to inject malicious JavaScript. This affects all emlog users up to pro-...

CVE-2025-5119

HIGH CVSS 7.3 May 23, 2025

This critical SQL injection vulnerability in Emlog Pro allows remote attackers to manipulate database queries through the 'tag' parameter in api_controller.php. Successful exploitation could lead to d...

CVE-2025-25823

HIGH CVSS 7.3 Feb 26, 2025

This cross-site scripting vulnerability in Emlog Pro v2.5.4 allows attackers to inject malicious scripts into article headers via the admin interface. When exploited, it enables execution of arbitrary...

CVE-2025-25825

HIGH CVSS 7.1 Feb 26, 2025

This cross-site scripting vulnerability in Emlog Pro v2.5.4 allows attackers to inject malicious scripts into article category titles, which then execute in victims' browsers when viewing affected pag...

CVE-2023-41623

HIGH CVSS 7.2 Dec 12, 2023

Emlog Pro version 2.1.14 contains a SQL injection vulnerability in the uid parameter at /admin/media.php. This allows attackers to execute arbitrary SQL commands on the database. Only administrators w...

CVE-2023-39121

HIGH CVSS 7.2 Aug 3, 2023

CVE-2023-39121 is a SQL injection vulnerability in emlog v2.1.9 that allows attackers to execute arbitrary SQL commands via the /admin/user.php component. This affects all systems running the vulnerab...

CVE-2020-19028

HIGH CVSS 7.5 Jun 5, 2023

This vulnerability allows remote attackers to upload arbitrary files via the /admin/plugin.php endpoint in EmlogCMS v6.0.0. Attackers can gain unauthorized access to sensitive information or potential...

CVE-2026-21432

MEDIUM CVSS 5.4 Jan 2, 2026

Emlog 2.5.23 has a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When executed, these scripts can lead to account takeover, includin...

CVE-2026-21431

MEDIUM CVSS 5.4 Jan 2, 2026

Emlog 2.5.23 has a stored cross-site scripting vulnerability in the Resource Media Library function when publishing articles. This allows attackers to inject malicious scripts that execute when users ...

CVE-2026-21429

MEDIUM CVSS 4.3 Jan 2, 2026

This vulnerability in Emlog CMS allows administrators to restrict users from editing or deleting their own published articles. It affects all users of Emlog version 2.5.23 who have article publishing ...

CVE-2025-60447

MEDIUM CVSS 5.9 Oct 3, 2025

A stored XSS vulnerability in Emlog Pro 2.5.19 allows administrators to inject malicious HTML/JavaScript into email templates. This could lead to persistent script execution when other users view emai...

CVE-2025-9296

MEDIUM CVSS 4.7 Aug 21, 2025

Emlog Pro up to version 2.5.18 contains an unrestricted file upload vulnerability in the avatar update function. Attackers can remotely upload malicious files to affected systems, potentially leading ...

CVE-2025-53926

MEDIUM CVSS 6.1 Jul 16, 2025

Emlog website building system contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts via comment parameters. Attackers can steal session cookie...

CVE-2025-47786

MEDIUM CVSS 4.8 May 15, 2025

Emlog 2.5.13 has a stored XSS vulnerability where any registered user can inject malicious JavaScript via the 'perpage_num' parameter in comment.php. This JavaScript executes when other users view aff...

CVE-2025-25818

MEDIUM CVSS 5.1 Feb 26, 2025

This cross-site scripting (XSS) vulnerability in Emlog Pro allows attackers to inject malicious scripts into blog posts via the postStrVar function. Attackers can steal session cookies, redirect users...

CVE-2025-25827

MEDIUM CVSS 6.8 Feb 26, 2025

This Server-Side Request Forgery vulnerability in Emlog Pro allows attackers to make the vulnerable server send requests to internal network resources. Attackers can scan local ports and potentially a...

CVE-2024-12843

MEDIUM CVSS 4.3 Dec 20, 2024

This is a cross-site scripting (XSS) vulnerability in Emlog Pro's admin plugin management interface. Attackers can inject malicious scripts via the 'filter' parameter in /admin/plugin.php, potentially...

CVE-2024-12842

MEDIUM CVSS 4.3 Dec 20, 2024

This vulnerability allows attackers to inject malicious scripts via the 'keyword' parameter in Emlog Pro's /admin/user.php file, leading to cross-site scripting (XSS). It affects Emlog Pro users up to...

CVE-2024-12841

MEDIUM CVSS 4.3 Dec 20, 2024

This vulnerability allows attackers to inject malicious scripts into Emlog Pro blog management systems through the tag.php admin interface. Remote attackers can execute cross-site scripting attacks th...

CVE-2024-31612

MEDIUM CVSS 6.5 Jun 10, 2024

Emlog Pro 2.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in twitter.php that can be combined with Cross-Site Scripting (XSS) to access administrator information. This affects websites ...

CVE-2024-33752

MEDIUM CVSS 6.3 May 6, 2024

This vulnerability allows remote attackers to upload arbitrary files to emlog Pro installations, potentially leading to remote code execution. Attackers can exploit this by submitting specially crafte...