Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

emlog — Vulnerabilities & Security Advisories 41

All 41 CVE vulnerabilities found in emlog, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities specifically affecting the emlog product, a popular open-source blog management system. It collects reported security flaws, primarily categorized by Common Weakness Enumerations, covering advisories published over the past five years. Readers can use this hub to track emlog's security advisories, understand the specific weakness classes present in the software, and review the product's vulnerability history. The data supports security teams in assessing exposure, prioritizing patch management, and identifying recurring patterns in emlog's security posture without needing to search multiple disjointed sources.

Vendor: unspecified

CVE ID Title CVSS Severity Published
CVE-2026-73848 Emlog: Stored XSS via Tag Name in Article Editor CWE-79 6.9 Medium 2026-09-04
CVE-2026-53757 Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE CWE-22 6.9 Medium 2026-09-04
CVE-2026-53758 Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized CWE-79 8.7 High 2026-09-04
CVE-2026-53756 Emlog Blind SQL Injection via Authentication Cookie CWE-89 4.9 Medium 2026-09-04
CVE-2026-73850 Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function CWE-89 8.6 High 2026-08-14
CVE-2026-73849 emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. CWE-306 9.8 Critical 2026-08-14
CVE-2026-73847 Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover CWE-352 6.8 Medium 2026-08-14
CVE-2026-67598 Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php CWE-295 7.4 High 2026-08-03
CVE-2026-46687 Emlog Local File Inclusion (LFI) CWE-24 - - 2026-07-16
CVE-2026-46686 Emlog Reflected Cross-Site Scripting CWE-79 - - 2026-07-16
CVE-2026-42287 Emlog: SQL Injection Vulnerability in log_model.php within addLog() and updateLog() Functions CWE-89 8.8AI High AI 2026-05-08
CVE-2026-42286 Emlog: Cross-Site Request Forgery in Admin Functions CWE-352 6.5AI Medium AI 2026-05-08
CVE-2026-41517 Emlog: Remote Code Execution via Malicious Plugin Upload CWE-434 9.8AI Critical AI 2026-05-08
CVE-2026-34788 Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parameters CWE-89 6.5 Medium 2026-04-03
CVE-2026-34787 Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameter CWE-98 6.5 Medium 2026-04-03
CVE-2026-34607 Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE CWE-22 7.2 High 2026-04-03
CVE-2026-34229 Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypass CWE-79 6.1 Medium 2026-04-03
CVE-2026-34228 Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write CWE-352 8.8AI High AI 2026-04-03
CVE-2026-31954 Emlog asynchronous media file deletion missing CSRF protection CWE-352 - - 2026-03-11
CVE-2026-22799 emlog Arbitrary File Upload Vulnerability CWE-434 7.2AI High AI 2026-01-12
CVE-2026-21433 Emlog vulnerable to Server-Side Request Forgery (SSRF) CWE-918 7.7 High 2026-01-02
CVE-2026-21432 Emlog has stored Cross-site Scripting issue that can lead to admin or another account ATO CWE-79 7.6 - 2026-01-02
CVE-2026-21431 Emlog vulnerable to stored Cross-site Scripting via image name CWE-79 5.4 - 2026-01-02
CVE-2026-21430 Emlog: CSRF chained with stored XSS leads to ATO CWE-352 8.3 - 2026-01-02
CVE-2026-21429 Emlog has Broken Access Control (BAC) CWE-862 3.8 - 2026-01-02
CVE-2025-62717 Emlog Pro session verification code error due to clearing logic error CWE-287 8.1 - 2025-10-24
CVE-2025-61930 Emlog Pro has CSRF issue that Enables Admin Password Reset CWE-352 8.1 High 2025-10-10
CVE-2025-61769 Emlog vulnerable to stored XSS in file upload functionality in emlog CWE-79 5.4AI Medium AI 2025-10-06
CVE-2025-61599 Emlog is Vulnerable to Stored Cross-Site Scripting (XSS) in "Twitter" Feature via Markdown Input CWE-79 5.4 - 2025-10-03
CVE-2025-61597 Emlog Pro is vulnerable to stored XSS attack through HTML template injection CWE-79 7.6 High 2025-10-03

All 41 known CVE vulnerabilities affecting emlog with full Chinese analysis, references, and POCs where available.