Emlog

Emlog

103 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 14.08.2026 17:46:26
  • Zuletzt bearbeitet 17.08.2026 19:16:42

Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php.

  • EPSS 0.48%
  • Veröffentlicht 14.08.2026 17:37:20
  • Zuletzt bearbeitet 18.08.2026 02:17:30

Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote atta...

  • EPSS 0.17%
  • Veröffentlicht 14.08.2026 17:33:02
  • Zuletzt bearbeitet 14.08.2026 20:16:58

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-control...

  • EPSS 0.2%
  • Veröffentlicht 03.08.2026 21:16:40
  • Zuletzt bearbeitet 05.08.2026 20:17:09

Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator ...

  • EPSS 0.16%
  • Veröffentlicht 03.08.2026 19:02:06
  • Zuletzt bearbeitet 04.08.2026 14:16:32

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certif...

  • EPSS 0.29%
  • Veröffentlicht 16.07.2026 17:01:31
  • Zuletzt bearbeitet 17.07.2026 18:04:04

Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls ...

  • EPSS 0.32%
  • Veröffentlicht 16.07.2026 16:59:17
  • Zuletzt bearbeitet 17.07.2026 18:04:04

Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php is processed with addslashes but not HTML-escaped before being rendered into the value attribute in a...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 29.05.2026 16:16:26
  • Zuletzt bearbeitet 21.07.2026 15:10:00

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an at...

  • EPSS 0.25%
  • Veröffentlicht 08.05.2026 21:51:52
  • Zuletzt bearbeitet 12.05.2026 16:45:18

Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially leading to complete database compromise, data thef...

  • EPSS 0.17%
  • Veröffentlicht 08.05.2026 21:51:11
  • Zuletzt bearbeitet 12.05.2026 16:45:18

Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing unauthorized actions like system registration, plugin...