Emlog

Emlog

86 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 09.06.2025 16:00:16
  • Zuletzt bearbeitet 20.06.2025 14:51:42

A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin/article.php. The manipulation of the argument active_post leads to cross site scripting. The attack may be ini...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 23.05.2025 21:00:11
  • Zuletzt bearbeitet 10.06.2025 19:34:07

A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be ...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 15.05.2025 19:33:24
  • Zuletzt bearbeitet 12.06.2025 16:39:25

Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that allows any registered user to construct malicious JavaScript, inducing all website users to click. In `/admin/comment.php`, the param...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 15.05.2025 19:29:23
  • Zuletzt bearbeitet 12.06.2025 16:39:17

Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordina...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 15.05.2025 19:27:03
  • Zuletzt bearbeitet 01.07.2025 14:42:21

Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded...

  • EPSS 0.31%
  • Veröffentlicht 15.05.2025 19:21:15
  • Zuletzt bearbeitet 20.10.2025 17:19:08

Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deseriali...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 28.03.2025 14:51:41
  • Zuletzt bearbeitet 14.04.2025 14:49:16

Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controller.php` does not use addslashes after urldecode, allowing the preceeding addslashes to be bypassed by ...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 19.03.2025 00:00:00
  • Zuletzt bearbeitet 12.06.2025 19:35:35

An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.

Exploit
  • EPSS 0.69%
  • Veröffentlicht 19.03.2025 00:00:00
  • Zuletzt bearbeitet 16.06.2025 18:49:10

An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • EPSS 0.03%
  • Veröffentlicht 26.02.2025 15:15:28
  • Zuletzt bearbeitet 07.04.2025 18:52:44

A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php.