emlog records
93 published records for vendor emlog.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 3.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')43
- CWE-434 Unrestricted Upload of File with Dangerous Type14
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-287 Improper Authentication2
The weakness classes this vendor ships most often: where to look.
CWEAll records
93 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2023-44974No exploit | An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code viaemlog · emlog · CWE-434 | Critical9.8 | — | 19.1% | Oct 3, 2023 |
40Plan | CVE-2021-31737No exploit | emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.emlog · emlog · CWE-434 | Critical9.8 | — | 3.9% | May 6, 2021 |
40Plan | CVE-2020-21585No exploit | Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.emlog · emlog · CWE-434 | Critical9.8 | — | 3.2% | Apr 2, 2021 |
40Plan | CVE-2021-40883No exploit | A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.emlog · emlog · CWE-434 | Critical9.8 | — | 3.0% | Dec 14, 2021 |
40Plan | CVE-2019-16868No exploit | emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traveremlog · emlog · CWE-22 | Critical9.8 | — | 2.6% | Sep 25, 2019 |
40Plan | CVE-2023-43291No exploit | Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php comemlog · emlog · CWE-502 | Critical9.8 | — | 1.9% | Sep 27, 2023 |
39Monitor | CVE-2022-23379No exploit | Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().emlog · emlog · CWE-89 | Critical9.8 | — | 1.4% | Feb 4, 2022 |
39Monitor | CVE-2023-44973No exploit | An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code vemlog · emlog · CWE-434 | Critical9.8 | — | 1.0% | Oct 3, 2023 |
39Monitor | CVE-2025-29401No exploit | An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code viaemlog · emlog · CWE-94 | Critical9.8 | — | 0.8% | Mar 19, 2025 |
39Monitor | CVE-2025-25783No exploit | An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via emlog · emlog · CWE-434 | Critical9.8 | — | 0.7% | Feb 26, 2025 |
37Monitor | CVE-2026-22799No exploit | emlog Arbitrary File Upload Vulnerabilityemlog · emlog · CWE-434 | Critical9.3 | — | 0.7% | Jan 12, 2026 |
36Monitor | CVE-2025-61318No exploit | Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.emlog · emlog · CWE-24 | Critical9.1 | — | 0.7% | Dec 8, 2025 |
35Monitor | CVE-2021-30081No exploit | An issue was discovered in emlog 6.0.0stable.emlog · emlog · CWE-89 | High8.8 | — | 1.0% | May 24, 2021 |
35Monitor | CVE-2025-47785No exploit | EMLOG SQL Injection Vulnerabilityemlog · emlog · CWE-89 | High8.8 | — | 0.8% | May 15, 2025 |
35Monitor | CVE-2025-47787No exploit | Emlog Pro Contains a File Upload Vulnerabilityemlog · emlog · CWE-434 | High8.9 | — | 0.7% | May 15, 2025 |
35Monitor | CVE-2018-18316No exploit | emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.emlog · emlog · CWE-352 | High8.8 | — | 0.5% | Oct 15, 2018 |
35Monitor | CVE-2025-61930No exploit | Emlog Pro has CSRF issue that Enables Admin Password Resetemlog · emlog · CWE-352 | High8.8 | — | 0.2% | Oct 10, 2025 |
34Monitor | CVE-2026-34228No exploit | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog · emlog · CWE-352 | High8.7 | — | 0.2% | Apr 3, 2026 |
30Monitor | CVE-2020-19028No exploit | *File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/pemlog · emlog · CWE-434 | High7.5 | — | 1.1% | Jun 5, 2023 |
30Monitor | CVE-2025-30372No exploit | Emlog Pro contains an SQL injection vulnerability.emlog · emlog · CWE-89 | High7.7 | — | 0.5% | Mar 28, 2025 |
30Monitor | CVE-2026-21433No exploit | Emlog vulnerable to Server-Side Request Forgery (SSRF)emlog · emlog · CWE-918 | High7.7 | — | 0.3% | Jan 2, 2026 |
29Monitor | CVE-2023-39121Proof of concept | emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.emlog · emlog · CWE-89 | High7.2 | — | 2.5% | Aug 3, 2023 |
29Monitor | CVE-2025-25823No exploit | A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a craemlog · emlog · CWE-79 | High7.3 | — | 0.2% | Feb 26, 2025 |
29Monitor | CVE-2026-31954No exploit | Emlog asynchronous media file deletion missing CSRF protectionemlog · emlog · CWE-352 | High7.3 | — | 0.2% | Mar 11, 2026 |
28Monitor | CVE-2022-42189No exploit | Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.emlog · emlog · CWE-434 | High7.2 | — | 1.6% | Oct 21, 2022 |
- CVE-2023-4497445Plan
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via
CriticalCVSS 9.8No exploitEPSS 19%emlog · emlogOct 3, 2023
- CVE-2021-3173740Plan
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
CriticalCVSS 9.8No exploitEPSS 4%emlog · emlogMay 6, 2021
- CVE-2020-2158540Plan
Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.
CriticalCVSS 9.8No exploitEPSS 3%emlog · emlogApr 2, 2021
- CVE-2021-4088340Plan
A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
CriticalCVSS 9.8No exploitEPSS 3%emlog · emlogDec 14, 2021
- CVE-2019-1686840Plan
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traver
CriticalCVSS 9.8No exploitEPSS 3%emlog · emlogSep 25, 2019
- CVE-2023-4329140Plan
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php com
CriticalCVSS 9.8No exploitEPSS 2%emlog · emlogSep 27, 2023
- CVE-2022-2337939Monitor
Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().
CriticalCVSS 9.8No exploitEPSS 1%emlog · emlogFeb 4, 2022
- CVE-2023-4497339Monitor
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code v
CriticalCVSS 9.8No exploitEPSS 1%emlog · emlogOct 3, 2023
- CVE-2025-2940139Monitor
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via
CriticalCVSS 9.8No exploitEPSS 1%emlog · emlogMar 19, 2025
- CVE-2025-2578339Monitor
An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via
CriticalCVSS 9.8No exploitEPSS 1%emlog · emlogFeb 26, 2025
- CVE-2026-2279937Monitor
emlog Arbitrary File Upload Vulnerability
CriticalCVSS 9.3No exploitEPSS 1%emlog · emlogJan 12, 2026
- CVE-2025-6131836Monitor
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.
CriticalCVSS 9.1No exploitEPSS 1%emlog · emlogDec 8, 2025
- CVE-2021-3008135Monitor
An issue was discovered in emlog 6.0.0stable.
HighCVSS 8.8No exploitEPSS 1%emlog · emlogMay 24, 2021
- CVE-2025-4778535Monitor
EMLOG SQL Injection Vulnerability
HighCVSS 8.8No exploitEPSS 1%emlog · emlogMay 15, 2025
- CVE-2025-4778735Monitor
Emlog Pro Contains a File Upload Vulnerability
HighCVSS 8.9No exploitEPSS 1%emlog · emlogMay 15, 2025
- CVE-2018-1831635Monitor
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
HighCVSS 8.8No exploitEPSS 1%emlog · emlogOct 15, 2018
- CVE-2025-6193035Monitor
Emlog Pro has CSRF issue that Enables Admin Password Reset
HighCVSS 8.8No exploitEPSS 0%emlog · emlogOct 10, 2025
- CVE-2026-3422834Monitor
Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write
HighCVSS 8.7No exploitEPSS 0%emlog · emlogApr 3, 2026
- CVE-2020-1902830Monitor
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/p
HighCVSS 7.5No exploitEPSS 1%emlog · emlogJun 5, 2023
- CVE-2025-3037230Monitor
Emlog Pro contains an SQL injection vulnerability.
HighCVSS 7.7No exploitEPSS 1%emlog · emlogMar 28, 2025
- CVE-2026-2143330Monitor
Emlog vulnerable to Server-Side Request Forgery (SSRF)
HighCVSS 7.7No exploitEPSS 0%emlog · emlogJan 2, 2026
- CVE-2023-3912129Monitor
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
HighCVSS 7.2Proof of conceptEPSS 3%emlog · emlogAug 3, 2023
- CVE-2025-2582329Monitor
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a cra
HighCVSS 7.3No exploitEPSS 0%emlog · emlogFeb 26, 2025
- CVE-2026-3195429Monitor
Emlog asynchronous media file deletion missing CSRF protection
HighCVSS 7.3No exploitEPSS 0%emlog · emlogMar 11, 2026
- CVE-2022-4218928Monitor
Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.
HighCVSS 7.2No exploitEPSS 2%emlog · emlogOct 21, 2022