Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2026-39276 The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP co… Emlog No fix yet Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-34788 Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag_model.php at … Emlog after 2.6.2 Fix from $1,6002026-04-03 HIGH 7.2 CVE-2026-34607 Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (includ… Emlog after 2.6.2 Fix from $1,9502026-04-03 MEDIUM 6.5 CVE-2026-34228 Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQL and ZIP URLs via GET parame… Emlog 2.6.8+ Fix from $1,6002026-04-03 MEDIUM 6.5 CVE-2026-34787 Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php a… Emlog after 2.6.2 Fix from $1,6002026-04-03 MEDIUM 6.1 CVE-2026-34229 Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment … Emlog 2.6.8+ Fix from $1,6002026-04-03 HIGH 7.3 CVE-2026-31954 Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::check… Emlog after 2.6.6 Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-22799 Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file upl… Emlog 2.6.1+ Fix from $1,9502026-01-12 HIGH 7.7 CVE-2026-21433 Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF … Emlog after 2.5.19 Fix from $1,9502026-01-02 MEDIUM 5.4 CVE-2026-21432 Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can lead to account takeover, in… Emlog No fix yet Fix from $1,6002026-01-02 CRITICAL 9.3 CVE-2026-21430 Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF)… Emlog No fix yet Fix from $2,3002026-01-02 MEDIUM 5.4 CVE-2026-21431 Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `Resource media library ` func… Emlog No fix yet Fix from $1,6002026-01-02 CRITICAL 9.1 CVE-2025-61318 Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.ph… Emlog No fix yet Fix from $2,3002025-12-08 CRITICAL 9.1 CVE-2025-62717 Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing lo… Emlog Patch available Fix from $2,3002025-10-24 HIGH 8.8 CVE-2025-61930 Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the pas… Emlog after 2.5.19 Fix from $1,9502025-10-10 MEDIUM 6.1 CVE-2025-61769 Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authen… Emlog 2.5.22+ Fix from $1,6002025-10-06 MEDIUM 6.1 CVE-2025-60448 A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of… Emlog No fix yet Fix from $1,6002025-10-03 MEDIUM 5.9 CVE-2025-60447 A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configurati… Emlog No fix yet Fix from $1,6002025-10-03 MEDIUM 5.4 CVE-2025-61597 Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored cross‑site scripting (XSS) vi… Emlog after 2.5.19 Fix from $1,6002025-10-03 MEDIUM 5.4 CVE-2025-61599 Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitter"feature of EMLOG Pro 2.5.21… Emlog after 2.5.21 Fix from $1,6002025-10-03 CRITICAL 9.8 CVE-2025-9296 A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_a… Emlog after 2.5.18 Fix from $2,3002025-08-21 HIGH 7.2 CVE-2025-44139 Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip Emlog No fix yet Fix from $1,9502025-08-01 MEDIUM 6.1 CVE-2025-53926 Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote att… Emlog after 2.5.17 Fix from $1,6002025-07-16 MEDIUM 5.4 CVE-2025-53925 Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authentica… Emlog after 2.5.17 Fix from $1,6002025-07-16 MEDIUM 6.1 CVE-2025-53923 Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote att… Emlog after 2.5.17 Fix from $1,6002025-07-16 CRITICAL 9.8 CVE-2025-5119 A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controlle… Emlog No fix yet Fix from $2,3002025-05-23 CRITICAL 9.8 CVE-2025-47787 Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component cont… Emlog 2.5.10+ Fix from $2,3002025-05-15 CRITICAL 9.8 CVE-2025-47784 Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully craft… Emlog 2.5.14+ Fix from $2,3002025-05-15 HIGH 8.8 CVE-2025-47785 Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in ad… Emlog after 2.5.9 Fix from $1,9502025-05-15 CRITICAL 9.8 CVE-2025-30372 Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controlle… Emlog 2.5.9+ Fix from $2,3002025-03-28