Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Emlog — Vulnerabilities & Security Advisories 37

All 37 CVE vulnerabilities found in Emlog, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities associated with the emlog open-source blogging platform, categorized under various weakness types such as injection, cross-site scripting, and broken access control. The collection aggregates data from vendor advisories, third-party security databases, and community reports, covering a broad historical time range that includes both resolved issues in legacy versions and recent disclosures in active releases. By centralizing this information, the resource allows researchers and administrators to track a vendor's advisory patterns and response times, understand the prevalence and nature of specific weakness classes within the emlog codebase, and look up a product's detailed vulnerability history to assess risk exposure. The content is structured to facilitate quick identification of affected versions, helping system owners determine whether their deployments are susceptible to public exploit techniques or require immediate patching. Entries include contextual details about severity ratings, attack vectors, and mitigation strategies where available, providing a comprehensive view of the security landscape surrounding this popular PHP-based CMS. This aggregation serves as a reference for security audits, penetration testing planning, and long-term maintenance decisions, ensuring that stakeholders have access to accurate and timely threat intelligence without navigating fragmented sources. The data is regularly updated to reflect the latest developments in the product's security posture and emerging threat trends.

Vendor: unspecified

CVE IDTitleCVSSSeverityPublished
CVE-2026-73850 Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function CWE-89 8.6 High2026-08-14
CVE-2026-73849 emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. CWE-306 9.8 Critical2026-08-14
CVE-2026-73847 Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover CWE-352 6.8 Medium2026-08-14
CVE-2026-67598 Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php CWE-295 7.4 High2026-08-03
CVE-2026-46687 Emlog Local File Inclusion (LFI) CWE-24--2026-07-16
CVE-2026-46686 Emlog Reflected Cross-Site Scripting CWE-79--2026-07-16
CVE-2026-42287 Emlog: SQL Injection Vulnerability in log_model.php within addLog() and updateLog() Functions CWE-89 8.8AIHighAI2026-05-08
CVE-2026-42286 Emlog: Cross-Site Request Forgery in Admin Functions CWE-352 6.5AIMediumAI2026-05-08
CVE-2026-41517 Emlog: Remote Code Execution via Malicious Plugin Upload CWE-434 9.8AICriticalAI2026-05-08
CVE-2026-34788 Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parameters CWE-89 6.5 Medium2026-04-03
CVE-2026-34787 Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameter CWE-98 6.5 Medium2026-04-03
CVE-2026-34607 Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE CWE-22 7.2 High2026-04-03
CVE-2026-34229 Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypass CWE-79 6.1 Medium2026-04-03
CVE-2026-34228 Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write CWE-352 8.8AIHighAI2026-04-03
CVE-2026-31954 Emlog asynchronous media file deletion missing CSRF protection CWE-352--2026-03-11
CVE-2026-22799 emlog Arbitrary File Upload Vulnerability CWE-434 7.2AIHighAI2026-01-12
CVE-2026-21433 Emlog vulnerable to Server-Side Request Forgery (SSRF) CWE-918 7.7 High2026-01-02
CVE-2026-21432 Emlog has stored Cross-site Scripting issue that can lead to admin or another account ATO CWE-79 7.6 -2026-01-02
CVE-2026-21431 Emlog vulnerable to stored Cross-site Scripting via image name CWE-79 5.4 -2026-01-02
CVE-2026-21430 Emlog: CSRF chained with stored XSS leads to ATO CWE-352 8.3 -2026-01-02
CVE-2026-21429 Emlog has Broken Access Control (BAC) CWE-862 3.8 -2026-01-02
CVE-2025-62717 Emlog Pro session verification code error due to clearing logic error CWE-287 8.1 -2025-10-24
CVE-2025-61930 Emlog Pro has CSRF issue that Enables Admin Password Reset CWE-352 8.1 High2025-10-10
CVE-2025-61769 Emlog vulnerable to stored XSS in file upload functionality in emlog CWE-79 5.4AIMediumAI2025-10-06
CVE-2025-61599 Emlog is Vulnerable to Stored Cross-Site Scripting (XSS) in "Twitter" Feature via Markdown Input CWE-79 5.4 -2025-10-03
CVE-2025-61597 Emlog Pro is vulnerable to stored XSS attack through HTML template injection CWE-79 7.6 High2025-10-03
CVE-2025-53926 Emlog has Stored Cross-site Scripting vulnerability due to error CWE-79 6.1 Medium2025-07-16
CVE-2025-53925 Emlog has Stored Cross-site Scripting vulnerability in file upload functionality CWE-79 5.4 Medium2025-07-16
CVE-2025-53924 Emlog vulnerable to stored Cross-site Scripting in links functionality CWE-79 6.9 Medium2025-07-16
CVE-2025-53923 Emlog vulnerable to reflected Cross-site Scripting in admin panel CWE-79 8.2 High2025-07-16

All 37 known CVE vulnerabilities affecting Emlog with full Chinese analysis, references, and POCs where available.