Emlog

Emlog

92 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 03.04.2026 22:37:08
  • Zuletzt bearbeitet 13.04.2026 17:29:51

Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag_model.php at line 168. The updateTagName() function directly interpolates user input into the SQL query string wit...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 03.04.2026 22:36:36
  • Zuletzt bearbeitet 13.04.2026 17:32:52

Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php at line 80. The $plugin parameter from the GET request is directly used in a require_once path without...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 03.04.2026 22:35:56
  • Zuletzt bearbeitet 13.04.2026 17:37:26

Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting ZIP archives (plugin/template uploads, backup imports), the fu...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 03.04.2026 22:31:44
  • Zuletzt bearbeitet 13.04.2026 17:37:40

Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment module via URI scheme validation bypass. This issue has been patched in version 2.6.8.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 03.04.2026 22:28:45
  • Zuletzt bearbeitet 13.04.2026 17:38:32

Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQL and ZIP URLs via GET parameters. The server first downloads and executes the SQL file, then downloads the ZIP file and extracts ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 11.03.2026 19:21:52
  • Zuletzt bearbeitet 17.03.2026 21:05:16

Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 12.01.2026 22:05:01
  • Zuletzt bearbeitet 21.01.2026 19:13:49

Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allow...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.01.2026 19:00:22
  • Zuletzt bearbeitet 16.01.2026 18:11:24

Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF via uploaded SVG files. An attacker can upload a crafted SVG to http[:]//emblog/admin/media[.]php whi...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.01.2026 18:58:38
  • Zuletzt bearbeitet 16.01.2026 17:13:09

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can lead to account takeover, including takeover of admin accounts. As of time of publication, no known patched versions are availabl...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.01.2026 18:49:03
  • Zuletzt bearbeitet 16.01.2026 17:13:01

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `Resource media library ` function while publishing an article. As of time of publication, no known patched versions are available.