Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

emlog — Vulnerabilities & Security Advisories 40

Browse all 40 CVE security advisories affecting emlog. AI-powered Chinese analysis, POCs, and references for each vulnerability.

emlog is an open-source PHP-based content management system designed for personal blogging and lightweight website deployment. Its architecture relies on a modular plugin structure and a MySQL backend, appealing to users seeking simplicity over complex enterprise frameworks. Security audits have identified twenty-seven Common Vulnerabilities and Exposures (CVEs) associated with the platform, predominantly stemming from insufficient input validation and inadequate access controls. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE) via crafted plugin files, Cross-Site Scripting (XSS) through unsanitized user inputs, and SQL Injection in legacy database queries. Privilege escalation flaws have also been documented, allowing authenticated users to bypass administrative restrictions. These issues often arise from outdated codebases and delayed patching cycles, highlighting the risks inherent in maintaining smaller, community-driven projects without rigorous, continuous security oversight.

Top products by emlog: emlog Pro
CVE ID Title CVSS Severity Published
CVE-2026-73848 Emlog: Stored XSS via Tag Name in Article Editor — emlog CWE-79 6.9 Medium 2026-09-04
CVE-2026-53757 Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE — emlog CWE-22 6.9 Medium 2026-09-04
CVE-2026-53758 Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized — emlog CWE-79 8.7 High 2026-09-04
CVE-2026-53756 Emlog Blind SQL Injection via Authentication Cookie — emlog CWE-89 4.9 Medium 2026-09-04
CVE-2026-73850 Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function — emlog CWE-89 8.6 High 2026-08-14
CVE-2026-73849 emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. — emlog CWE-306 9.8 Critical 2026-08-14
CVE-2026-73847 Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover — emlog CWE-352 6.8 Medium 2026-08-14
CVE-2026-67598 Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php — emlog CWE-295 7.4 High 2026-08-03
CVE-2026-46687 Emlog Local File Inclusion (LFI) — emlog CWE-24 - - 2026-07-16
CVE-2026-46686 Emlog Reflected Cross-Site Scripting — emlog CWE-79 - - 2026-07-16
CVE-2026-42287 Emlog: SQL Injection Vulnerability in log_model.php within addLog() and updateLog() Functions — emlog CWE-89 8.8AI High AI 2026-05-08
CVE-2026-42286 Emlog: Cross-Site Request Forgery in Admin Functions — emlog CWE-352 6.5AI Medium AI 2026-05-08
CVE-2026-41517 Emlog: Remote Code Execution via Malicious Plugin Upload — emlog CWE-434 9.8AI Critical AI 2026-05-08
CVE-2026-34788 Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parameters — emlog CWE-89 6.5 Medium 2026-04-03
CVE-2026-34787 Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameter — emlog CWE-98 6.5 Medium 2026-04-03
CVE-2026-34607 Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE — emlog CWE-22 7.2 High 2026-04-03
CVE-2026-34229 Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypass — emlog CWE-79 6.1 Medium 2026-04-03
CVE-2026-34228 Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write — emlog CWE-352 8.8AI High AI 2026-04-03
CVE-2026-31954 Emlog asynchronous media file deletion missing CSRF protection — emlog CWE-352 - - 2026-03-11
CVE-2026-22799 emlog Arbitrary File Upload Vulnerability — emlog CWE-434 7.2AI High AI 2026-01-12
CVE-2026-21433 Emlog vulnerable to Server-Side Request Forgery (SSRF) — emlog CWE-918 7.7 High 2026-01-02
CVE-2026-21432 Emlog has stored Cross-site Scripting issue that can lead to admin or another account ATO — emlog CWE-79 7.6 - 2026-01-02
CVE-2026-21431 Emlog vulnerable to stored Cross-site Scripting via image name — emlog CWE-79 5.4 - 2026-01-02
CVE-2026-21430 Emlog: CSRF chained with stored XSS leads to ATO — emlog CWE-352 8.3 - 2026-01-02
CVE-2026-21429 Emlog has Broken Access Control (BAC) — emlog CWE-862 3.8 - 2026-01-02
CVE-2025-62717 Emlog Pro session verification code error due to clearing logic error — emlog CWE-287 8.1 - 2025-10-24
CVE-2025-61930 Emlog Pro has CSRF issue that Enables Admin Password Reset — emlog CWE-352 8.1 High 2025-10-10
CVE-2025-61769 Emlog vulnerable to stored XSS in file upload functionality in emlog — emlog CWE-79 5.4AI Medium AI 2025-10-06
CVE-2025-61599 Emlog is Vulnerable to Stored Cross-Site Scripting (XSS) in "Twitter" Feature via Markdown Input — emlog CWE-79 5.4 - 2025-10-03
CVE-2025-61597 Emlog Pro is vulnerable to stored XSS attack through HTML template injection — emlog CWE-79 7.6 High 2025-10-03

This page lists every published CVE security advisory associated with emlog. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.