Emlog

Emlog

86 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.34%
  • Veröffentlicht 12.01.2026 22:05:01
  • Zuletzt bearbeitet 21.01.2026 19:13:49

Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allow...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.01.2026 19:00:22
  • Zuletzt bearbeitet 16.01.2026 18:11:24

Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF via uploaded SVG files. An attacker can upload a crafted SVG to http[:]//emblog/admin/media[.]php whi...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.01.2026 18:58:38
  • Zuletzt bearbeitet 16.01.2026 17:13:09

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can lead to account takeover, including takeover of admin accounts. As of time of publication, no known patched versions are availabl...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.01.2026 18:49:03
  • Zuletzt bearbeitet 16.01.2026 17:13:01

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `Resource media library ` function while publishing an article. As of time of publication, no known patched versions are available.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 02.01.2026 18:44:24
  • Zuletzt bearbeitet 16.01.2026 19:07:18

Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 02.01.2026 17:23:17
  • Zuletzt bearbeitet 16.01.2026 17:11:08

Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable to edit or delete their articles after publishing them. As of time of publication, no known patched versions are available.

Exploit
  • EPSS 1.31%
  • Veröffentlicht 08.12.2025 00:00:00
  • Zuletzt bearbeitet 09.12.2025 16:17:50

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion paramet...

  • EPSS 0.06%
  • Veröffentlicht 24.10.2025 20:13:47
  • Zuletzt bearbeitet 28.10.2025 14:15:50

Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is re...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 10.10.2025 20:15:38
  • Zuletzt bearbeitet 20.10.2025 16:47:37

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change endpoint. An attacker can trick a logged‑in administrator into submitting a crafted POST...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 06.10.2025 16:09:53
  • Zuletzt bearbeitet 09.10.2025 16:48:42

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As...