CVE-2025-9296
- EPSS 0.1%
- Veröffentlicht 21.08.2025 11:32:06
- Zuletzt bearbeitet 12.09.2025 13:10:41
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch...
CVE-2025-44139
- EPSS 0.09%
- Veröffentlicht 01.08.2025 00:00:00
- Zuletzt bearbeitet 13.08.2025 15:00:26
Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip
CVE-2025-53926
- EPSS 0.06%
- Veröffentlicht 16.07.2025 15:37:44
- Zuletzt bearbeitet 14.08.2025 20:37:42
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS r...
CVE-2025-53925
- EPSS 0.04%
- Veröffentlicht 16.07.2025 14:21:42
- Zuletzt bearbeitet 14.08.2025 20:38:06
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an ...
CVE-2025-53924
- EPSS 0.07%
- Veröffentlicht 16.07.2025 13:55:57
- Zuletzt bearbeitet 18.07.2025 15:15:28
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible...
CVE-2025-53923
- EPSS 0.07%
- Veröffentlicht 16.07.2025 13:53:11
- Zuletzt bearbeitet 22.07.2025 15:15:37
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization ...
CVE-2025-5886
- EPSS 0.2%
- Veröffentlicht 09.06.2025 16:00:16
- Zuletzt bearbeitet 20.06.2025 14:51:42
A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin/article.php. The manipulation of the argument active_post leads to cross site scripting. The attack may be ini...
CVE-2025-5119
- EPSS 0.22%
- Veröffentlicht 23.05.2025 21:00:11
- Zuletzt bearbeitet 10.06.2025 19:34:07
A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be ...
CVE-2025-47786
- EPSS 0.14%
- Veröffentlicht 15.05.2025 19:33:24
- Zuletzt bearbeitet 12.06.2025 16:39:25
Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that allows any registered user to construct malicious JavaScript, inducing all website users to click. In `/admin/comment.php`, the param...
CVE-2025-47785
- EPSS 1.57%
- Veröffentlicht 15.05.2025 19:29:23
- Zuletzt bearbeitet 12.06.2025 16:39:17
Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordina...