Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Emlog HIGH 7.2
CVE-2026-39276

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP co…

No fix yet
Fix from $1,950 2026-05-29
Emlog MEDIUM 6.5
CVE-2026-34788

Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag_model.php at …

Fix: after 2.6.2
Fix from $1,600 2026-04-03
Emlog HIGH 7.2
CVE-2026-34607

Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (includ…

Fix: after 2.6.2
Fix from $1,950 2026-04-03
Emlog MEDIUM 6.5
CVE-2026-34228

Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQL and ZIP URLs via GET parame…

Fix: 2.6.8+
Fix from $1,600 2026-04-03
Emlog MEDIUM 6.5
CVE-2026-34787

Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php a…

Fix: after 2.6.2
Fix from $1,600 2026-04-03
Emlog MEDIUM 6.1
CVE-2026-34229

Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment …

Fix: 2.6.8+
Fix from $1,600 2026-04-03
Emlog HIGH 7.3
CVE-2026-31954

Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::check…

Fix: after 2.6.6
Fix from $1,950 2026-03-11
Emlog HIGH 8.8
CVE-2026-22799

Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file upl…

Fix: 2.6.1+
Fix from $1,950 2026-01-12
Emlog HIGH 7.7
CVE-2026-21433

Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF …

Fix: after 2.5.19
Fix from $1,950 2026-01-02
Emlog MEDIUM 5.4
CVE-2026-21432

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can lead to account takeover, in…

No fix yet
Fix from $1,600 2026-01-02
Emlog CRITICAL 9.3
CVE-2026-21430

Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF)…

No fix yet
Fix from $2,300 2026-01-02
Emlog MEDIUM 5.4
CVE-2026-21431

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `Resource media library ` func…

No fix yet
Fix from $1,600 2026-01-02
Emlog CRITICAL 9.1
CVE-2025-61318

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.ph…

No fix yet
Fix from $2,300 2025-12-08
Emlog CRITICAL 9.1
CVE-2025-62717

Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing lo…

Patch available
Fix from $2,300 2025-10-24
Emlog HIGH 8.8
CVE-2025-61930

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the pas…

Fix: after 2.5.19
Fix from $1,950 2025-10-10
Emlog MEDIUM 6.1
CVE-2025-61769

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authen…

Fix: 2.5.22+
Fix from $1,600 2025-10-06
Emlog MEDIUM 6.1
CVE-2025-60448

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of…

No fix yet
Fix from $1,600 2025-10-03
Emlog MEDIUM 5.9
CVE-2025-60447

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configurati…

No fix yet
Fix from $1,600 2025-10-03
Emlog MEDIUM 5.4
CVE-2025-61597

Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored cross‑site scripting (XSS) vi…

Fix: after 2.5.19
Fix from $1,600 2025-10-03
Emlog MEDIUM 5.4
CVE-2025-61599

Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitter"feature of EMLOG Pro 2.5.21…

Fix: after 2.5.21
Fix from $1,600 2025-10-03
Emlog CRITICAL 9.8
CVE-2025-9296

A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_a…

Fix: after 2.5.18
Fix from $2,300 2025-08-21
Emlog HIGH 7.2
CVE-2025-44139

Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip

No fix yet
Fix from $1,950 2025-08-01
Emlog MEDIUM 6.1
CVE-2025-53926

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote att…

Fix: after 2.5.17
Fix from $1,600 2025-07-16
Emlog MEDIUM 5.4
CVE-2025-53925

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authentica…

Fix: after 2.5.17
Fix from $1,600 2025-07-16
Emlog MEDIUM 6.1
CVE-2025-53923

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote att…

Fix: after 2.5.17
Fix from $1,600 2025-07-16
Emlog CRITICAL 9.8
CVE-2025-5119

A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controlle…

No fix yet
Fix from $2,300 2025-05-23
Emlog CRITICAL 9.8
CVE-2025-47787

Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component cont…

Fix: 2.5.10+
Fix from $2,300 2025-05-15
Emlog CRITICAL 9.8
CVE-2025-47784

Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully craft…

Fix: 2.5.14+
Fix from $2,300 2025-05-15
Emlog HIGH 8.8
CVE-2025-47785

Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in ad…

Fix: after 2.5.9
Fix from $1,950 2025-05-15
Emlog CRITICAL 9.8
CVE-2025-30372

Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controlle…

Fix: 2.5.9+
Fix from $2,300 2025-03-28