Emlog

Emlog

103 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.45%
  • Veröffentlicht 16.01.2024 01:15:34
  • Zuletzt bearbeitet 17.06.2025 16:15:23

Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.

Exploit
  • EPSS 0.48%
  • Veröffentlicht 14.12.2023 00:15:43
  • Zuletzt bearbeitet 21.11.2024 08:21:22

Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin/article.php?active_savedraft.

Exploit
  • EPSS 1.15%
  • Veröffentlicht 13.12.2023 23:15:07
  • Zuletzt bearbeitet 21.11.2024 08:21:22

A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.

Exploit
  • EPSS 0.84%
  • Veröffentlicht 12.12.2023 09:15:07
  • Zuletzt bearbeitet 21.11.2024 08:21:22

Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php.

Exploit
  • EPSS 1.03%
  • Veröffentlicht 03.10.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:26:10

An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Exploit
  • EPSS 19.06%
  • Veröffentlicht 03.10.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:26:10

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • EPSS 0.33%
  • Veröffentlicht 02.10.2023 21:15:34
  • Zuletzt bearbeitet 21.11.2024 08:23:54

A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title field.

Exploit
  • EPSS 1.55%
  • Veröffentlicht 27.09.2023 15:19:33
  • Zuletzt bearbeitet 21.11.2024 08:23:56

Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.

Exploit
  • EPSS 2.51%
  • Veröffentlicht 03.08.2023 20:15:11
  • Zuletzt bearbeitet 21.11.2024 08:14:45

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

Exploit
  • EPSS 0.7%
  • Veröffentlicht 26.07.2023 13:15:10
  • Zuletzt bearbeitet 21.11.2024 08:11:00

emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.