Vulnerability index

Browse CVEs

47 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-43267 A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or … Emlog Mitigation only Fix from $1,6002023-10-02 HIGH 7.2 CVE-2023-39121 emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php. Emlog No fix yet Fix from $1,9502023-08-03 MEDIUM 6.5 CVE-2023-37049 emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php. Emlog No fix yet Fix from $1,6002023-07-26 HIGH 7.5 CVE-2020-19028 *File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php… Emlog No fix yet Fix from $1,9502023-06-05 HIGH 7.2 CVE-2022-42189 Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability. Emlog No fix yet Fix from $1,9502022-10-21 CRITICAL 9.8 CVE-2022-23379 Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid(). Emlog No fix yet Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2021-40883 A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins. Emlog No fix yet Fix from $2,3002021-12-14 HIGH 7.2 CVE-2020-21654 emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file. Emlog No fix yet Fix from $1,9502021-10-06 HIGH 7.2 CVE-2020-21013 emlog v6.0.0 contains a SQL injection via /admin/comment.php. Emlog No fix yet Fix from $1,9502021-10-01 MEDIUM 6.5 CVE-2020-21014 emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php. Emlog No fix yet Fix from $1,6002021-10-01 HIGH 8.8 CVE-2021-30081 An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive da… Emlog No fix yet Fix from $1,9502021-05-24 MEDIUM 6.1 CVE-2020-18194 Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post. Emlog No fix yet Fix from $1,6002021-05-17 CRITICAL 9.8 CVE-2021-31737 emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php. Emlog No fix yet Fix from $2,3002021-05-06 MEDIUM 6.1 CVE-2021-30227 Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0. Emlog No fix yet Fix from $1,6002021-04-29 CRITICAL 9.8 CVE-2020-21585 Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module. Emlog No fix yet Fix from $2,3002021-04-02 MEDIUM 5.3 CVE-2021-3293EPSS 21% emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file. Emlog No fix yet Fix from $1,6002021-02-08 HIGH 8.8 CVE-2018-18316 emlog v6.0.0 has CSRF via the admin/user.php?action=new URI. Emlog No fix yet Fix from $1,9502018-10-15