emlog是emlog开源的一套基于PHP和MySQL的CMS建站系统。 Emlog 2.5.19及之前版本存在代码问题漏洞,该漏洞源于通过上传SVG文件可能导致服务器端带外请求或服务端请求伪造,从而探测内部网络和泄露元数据或凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-21430 | Emlog: CSRF chained with stored XSS leads to ATO | |
| CVE-2026-21431 | Emlog vulnerable to stored Cross-site Scripting via image name | |
| CVE-2026-21432 | Emlog has stored Cross-site Scripting issue that can lead to admin or another account ATO | |
| CVE-2026-21429 | Emlog has Broken Access Control (BAC) |
No comments yet