CVE-2026-73848
- EPSS 0.32%
- Veröffentlicht 04.09.2026 17:47:58
- Zuletzt bearbeitet 08.09.2026 21:05:26
Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslashes() functio...
CVE-2026-53757
- EPSS -
- Veröffentlicht 04.09.2026 17:47:38
- Zuletzt bearbeitet 08.09.2026 21:05:26
Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory...
CVE-2026-53758
- EPSS -
- Veröffentlicht 04.09.2026 17:47:19
- Zuletzt bearbeitet 09.09.2026 18:16:59
Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML including <script> tags embedded in Markdown is passed through unescaped. The ou...
CVE-2026-53756
- EPSS -
- Veröffentlicht 04.09.2026 17:46:58
- Zuletzt bearbeitet 08.09.2026 21:05:26
Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filtering. The vu...
CVE-2026-73850
- EPSS 0.27%
- Veröffentlicht 14.08.2026 17:46:26
- Zuletzt bearbeitet 16.09.2026 13:42:42
Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php.
CVE-2026-73849
- EPSS 0.48%
- Veröffentlicht 14.08.2026 17:37:20
- Zuletzt bearbeitet 16.09.2026 13:42:42
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote atta...
CVE-2026-73847
- EPSS 0.17%
- Veröffentlicht 14.08.2026 17:33:02
- Zuletzt bearbeitet 16.09.2026 13:42:42
Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-control...
CVE-2026-52520
- EPSS 0.2%
- Veröffentlicht 03.08.2026 21:16:40
- Zuletzt bearbeitet 31.08.2026 19:33:11
Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator ...
CVE-2026-67598
- EPSS 0.16%
- Veröffentlicht 03.08.2026 19:02:06
- Zuletzt bearbeitet 09.09.2026 20:40:01
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certif...
CVE-2026-46687
- EPSS 0.29%
- Veröffentlicht 16.07.2026 17:01:31
- Zuletzt bearbeitet 17.07.2026 18:04:04
Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls ...