Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Emlog CRITICAL 9.8
CVE-2023-44974EPSS 19%

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploadin…

No fix yet
Fix from $2,300 2023-10-03
Emlog MEDIUM 5.4
CVE-2023-43267

A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or …

Mitigation only
Fix from $1,600 2023-10-02
Emlog CRITICAL 9.8
CVE-2023-43291

Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.

Fix: after 2.1.15
Fix from $2,300 2023-09-27
Emlog HIGH 7.2
CVE-2023-39121

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

No fix yet
Fix from $1,950 2023-08-03
Emlog MEDIUM 6.5
CVE-2023-37049

emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.

No fix yet
Fix from $1,600 2023-07-26
Emlog HIGH 7.5
CVE-2020-19028

*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php…

No fix yet
Fix from $1,950 2023-06-05
Emlog MEDIUM 5.4
CVE-2023-30338

Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafte…

Patch available
Fix from $1,600 2023-04-27
Emlog MEDIUM 6.1
CVE-2022-3968

A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/a…

Fix: 2022-11-08+
Fix from $1,600 2022-11-13
Emlog HIGH 7.2
CVE-2022-42189

Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.

No fix yet
Fix from $1,950 2022-10-21
Emlog MEDIUM 5.4
CVE-2022-1526

A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The m…

Fix: after 1.2.2
Fix from $1,600 2022-04-29
Emlog CRITICAL 9.8
CVE-2022-23379

Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().

No fix yet
Fix from $2,300 2022-02-04
Emlog MEDIUM 6.1
CVE-2021-44584

Cross-site scripting (XSS) vulnerability in index.php in emlog version <= pro-1.0.7 allows remote attackers to inject arbitrary web script or HTML vi…

Fix: after 1.0.7
Fix from $1,600 2022-01-06
Emlog CRITICAL 9.8
CVE-2021-40883

A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.

No fix yet
Fix from $2,300 2021-12-14
Emlog HIGH 7.2
CVE-2020-21654

emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.

No fix yet
Fix from $1,950 2021-10-06
Emlog HIGH 7.2
CVE-2020-21013

emlog v6.0.0 contains a SQL injection via /admin/comment.php.

No fix yet
Fix from $1,950 2021-10-01
Emlog MEDIUM 6.5
CVE-2020-21014

emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.

No fix yet
Fix from $1,600 2021-10-01
Emlog HIGH 8.8
CVE-2021-30081

An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive da…

No fix yet
Fix from $1,950 2021-05-24
Emlog MEDIUM 6.1
CVE-2020-18194

Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post.

No fix yet
Fix from $1,600 2021-05-17
Emlog CRITICAL 9.8
CVE-2021-31737

emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.

No fix yet
Fix from $2,300 2021-05-06
Emlog MEDIUM 6.1
CVE-2021-30227

Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0.

No fix yet
Fix from $1,600 2021-04-29
Emlog CRITICAL 9.8
CVE-2020-21585

Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.

No fix yet
Fix from $2,300 2021-04-02
Emlog MEDIUM 5.3
CVE-2021-3293EPSS 21%

emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.

No fix yet
Fix from $1,600 2021-02-08
Emlog MEDIUM 6.5
CVE-2019-17073

emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.

Fix: after 5.3.1
Fix from $1,600 2019-10-01
Emlog CRITICAL 9.8
CVE-2019-16868

emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal seque…

Fix: after 5.3.1
Fix from $2,300 2019-09-25
Emlog HIGH 8.8
CVE-2018-18316

emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.

No fix yet
Fix from $1,950 2018-10-15