CVE-2025-47785
- EPSS 0.74%
- Veröffentlicht 15.05.2025 19:29:23
- Zuletzt bearbeitet 12.06.2025 16:39:17
Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordina...
CVE-2025-47787
- EPSS 0.71%
- Veröffentlicht 15.05.2025 19:27:03
- Zuletzt bearbeitet 01.07.2025 14:42:21
Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded...
CVE-2025-47784
- EPSS 0.49%
- Veröffentlicht 15.05.2025 19:21:15
- Zuletzt bearbeitet 20.10.2025 17:19:08
Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deseriali...
CVE-2025-30372
- EPSS 0.52%
- Veröffentlicht 28.03.2025 14:51:41
- Zuletzt bearbeitet 14.04.2025 14:49:16
Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controller.php` does not use addslashes after urldecode, allowing the preceeding addslashes to be bypassed by ...
CVE-2025-29401
- EPSS 0.75%
- Veröffentlicht 19.03.2025 00:00:00
- Zuletzt bearbeitet 16.06.2025 18:49:10
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-29405
- EPSS 0.41%
- Veröffentlicht 19.03.2025 00:00:00
- Zuletzt bearbeitet 12.06.2025 19:35:35
An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-25818
- EPSS 0.17%
- Veröffentlicht 26.02.2025 15:15:28
- Zuletzt bearbeitet 05.07.2026 01:21:34
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the postStrVar function at article_save.php.
CVE-2025-25823
- EPSS 0.19%
- Veröffentlicht 26.02.2025 15:15:28
- Zuletzt bearbeitet 05.07.2026 01:21:35
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php.
CVE-2025-25825
- EPSS 0.18%
- Veröffentlicht 26.02.2025 15:15:28
- Zuletzt bearbeitet 05.07.2026 01:21:36
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.
CVE-2025-25827
- EPSS 0.16%
- Veröffentlicht 26.02.2025 15:15:28
- Zuletzt bearbeitet 05.07.2026 01:21:36
A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted URL.