Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2023-44974EPSS 19%
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploadin…
Emlog
No fix yet
MEDIUM 5.4
CVE-2023-43267
A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or …
Emlog
Mitigation only
CRITICAL 9.8
CVE-2023-43291
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.
Emlog
after 2.1.15
HIGH 7.2
CVE-2023-39121
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
Emlog
No fix yet
MEDIUM 6.5
CVE-2023-37049
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
Emlog
No fix yet
HIGH 7.5
CVE-2020-19028
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php…
Emlog
No fix yet
MEDIUM 5.4
CVE-2023-30338
Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafte…
Emlog
Patch available
MEDIUM 6.1
CVE-2022-3968
A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/a…
Emlog
2022-11-08+
HIGH 7.2
CVE-2022-42189
Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.
Emlog
No fix yet
MEDIUM 5.4
CVE-2022-1526
A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The m…
Emlog
after 1.2.2
CRITICAL 9.8
CVE-2022-23379
Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().
Emlog
No fix yet
MEDIUM 6.1
CVE-2021-44584
Cross-site scripting (XSS) vulnerability in index.php in emlog version <= pro-1.0.7 allows remote attackers to inject arbitrary web script or HTML vi…
Emlog
after 1.0.7
CRITICAL 9.8
CVE-2021-40883
A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
Emlog
No fix yet
HIGH 7.2
CVE-2020-21654
emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.
Emlog
No fix yet
HIGH 7.2
CVE-2020-21013
emlog v6.0.0 contains a SQL injection via /admin/comment.php.
Emlog
No fix yet
MEDIUM 6.5
CVE-2020-21014
emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.
Emlog
No fix yet
HIGH 8.8
CVE-2021-30081
An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive da…
Emlog
No fix yet
MEDIUM 6.1
CVE-2020-18194
Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post.
Emlog
No fix yet
CRITICAL 9.8
CVE-2021-31737
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
Emlog
No fix yet
MEDIUM 6.1
CVE-2021-30227
Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0.
Emlog
No fix yet
CRITICAL 9.8
CVE-2020-21585
Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.
Emlog
No fix yet
MEDIUM 5.3
CVE-2021-3293EPSS 21%
emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.
Emlog
No fix yet
MEDIUM 6.5
CVE-2019-17073
emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
Emlog
after 5.3.1
CRITICAL 9.8
CVE-2019-16868
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal seque…
Emlog
after 5.3.1
HIGH 8.8
CVE-2018-18316
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
Emlog
No fix yet