emlog kayıtları
emlog üreticisine ait 93 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %3,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')43
- CWE-434 Unrestricted Upload of File with Dangerous Type14
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-287 Improper Authentication2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
93 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2023-44974İstismar yok | An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code viaemlog · emlog · CWE-434 | Kritik9,8 | — | %19,1 | 3 Eki 2023 |
40Planlayın | CVE-2021-31737İstismar yok | emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.emlog · emlog · CWE-434 | Kritik9,8 | — | %3,9 | 6 May 2021 |
40Planlayın | CVE-2020-21585İstismar yok | Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.emlog · emlog · CWE-434 | Kritik9,8 | — | %3,2 | 2 Nis 2021 |
40Planlayın | CVE-2021-40883İstismar yok | A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.emlog · emlog · CWE-434 | Kritik9,8 | — | %3,0 | 14 Ara 2021 |
40Planlayın | CVE-2019-16868İstismar yok | emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traveremlog · emlog · CWE-22 | Kritik9,8 | — | %2,6 | 25 Eyl 2019 |
40Planlayın | CVE-2023-43291İstismar yok | Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php comemlog · emlog · CWE-502 | Kritik9,8 | — | %1,9 | 27 Eyl 2023 |
39İzleyin | CVE-2022-23379İstismar yok | Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().emlog · emlog · CWE-89 | Kritik9,8 | — | %1,4 | 4 Şub 2022 |
39İzleyin | CVE-2023-44973İstismar yok | An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code vemlog · emlog · CWE-434 | Kritik9,8 | — | %1,0 | 3 Eki 2023 |
39İzleyin | CVE-2025-29401İstismar yok | An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code viaemlog · emlog · CWE-94 | Kritik9,8 | — | %0,8 | 19 Mar 2025 |
39İzleyin | CVE-2025-25783İstismar yok | An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via emlog · emlog · CWE-434 | Kritik9,8 | — | %0,7 | 26 Şub 2025 |
37İzleyin | CVE-2026-22799İstismar yok | emlog Arbitrary File Upload Vulnerabilityemlog · emlog · CWE-434 | Kritik9,3 | — | %0,7 | 12 Oca 2026 |
36İzleyin | CVE-2025-61318İstismar yok | Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.emlog · emlog · CWE-24 | Kritik9,1 | — | %0,7 | 8 Ara 2025 |
35İzleyin | CVE-2021-30081İstismar yok | An issue was discovered in emlog 6.0.0stable.emlog · emlog · CWE-89 | Yüksek8,8 | — | %1,0 | 24 May 2021 |
35İzleyin | CVE-2025-47785İstismar yok | EMLOG SQL Injection Vulnerabilityemlog · emlog · CWE-89 | Yüksek8,8 | — | %0,8 | 15 May 2025 |
35İzleyin | CVE-2025-47787İstismar yok | Emlog Pro Contains a File Upload Vulnerabilityemlog · emlog · CWE-434 | Yüksek8,9 | — | %0,7 | 15 May 2025 |
35İzleyin | CVE-2018-18316İstismar yok | emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.emlog · emlog · CWE-352 | Yüksek8,8 | — | %0,5 | 15 Eki 2018 |
35İzleyin | CVE-2025-61930İstismar yok | Emlog Pro has CSRF issue that Enables Admin Password Resetemlog · emlog · CWE-352 | Yüksek8,8 | — | %0,2 | 10 Eki 2025 |
34İzleyin | CVE-2026-34228İstismar yok | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog · emlog · CWE-352 | Yüksek8,7 | — | %0,2 | 3 Nis 2026 |
30İzleyin | CVE-2020-19028İstismar yok | *File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/pemlog · emlog · CWE-434 | Yüksek7,5 | — | %1,1 | 5 Haz 2023 |
30İzleyin | CVE-2025-30372İstismar yok | Emlog Pro contains an SQL injection vulnerability.emlog · emlog · CWE-89 | Yüksek7,7 | — | %0,5 | 28 Mar 2025 |
30İzleyin | CVE-2026-21433İstismar yok | Emlog vulnerable to Server-Side Request Forgery (SSRF)emlog · emlog · CWE-918 | Yüksek7,7 | — | %0,3 | 2 Oca 2026 |
29İzleyin | CVE-2023-39121Kavram kanıtı | emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.emlog · emlog · CWE-89 | Yüksek7,2 | — | %2,5 | 3 Ağu 2023 |
29İzleyin | CVE-2025-25823İstismar yok | A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a craemlog · emlog · CWE-79 | Yüksek7,3 | — | %0,2 | 26 Şub 2025 |
29İzleyin | CVE-2026-31954İstismar yok | Emlog asynchronous media file deletion missing CSRF protectionemlog · emlog · CWE-352 | Yüksek7,3 | — | %0,2 | 11 Mar 2026 |
28İzleyin | CVE-2022-42189İstismar yok | Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.emlog · emlog · CWE-434 | Yüksek7,2 | — | %1,6 | 21 Eki 2022 |
- CVE-2023-4497445Planlayın
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via
KritikCVSS 9,8İstismar yokEPSS %19emlog · emlog3 Eki 2023
- CVE-2021-3173740Planlayın
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
KritikCVSS 9,8İstismar yokEPSS %4emlog · emlog6 May 2021
- CVE-2020-2158540Planlayın
Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.
KritikCVSS 9,8İstismar yokEPSS %3emlog · emlog2 Nis 2021
- CVE-2021-4088340Planlayın
A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
KritikCVSS 9,8İstismar yokEPSS %3emlog · emlog14 Ara 2021
- CVE-2019-1686840Planlayın
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traver
KritikCVSS 9,8İstismar yokEPSS %3emlog · emlog25 Eyl 2019
- CVE-2023-4329140Planlayın
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php com
KritikCVSS 9,8İstismar yokEPSS %2emlog · emlog27 Eyl 2023
- CVE-2022-2337939İzleyin
Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().
KritikCVSS 9,8İstismar yokEPSS %1emlog · emlog4 Şub 2022
- CVE-2023-4497339İzleyin
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code v
KritikCVSS 9,8İstismar yokEPSS %1emlog · emlog3 Eki 2023
- CVE-2025-2940139İzleyin
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via
KritikCVSS 9,8İstismar yokEPSS %1emlog · emlog19 Mar 2025
- CVE-2025-2578339İzleyin
An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via
KritikCVSS 9,8İstismar yokEPSS %1emlog · emlog26 Şub 2025
- CVE-2026-2279937İzleyin
emlog Arbitrary File Upload Vulnerability
KritikCVSS 9,3İstismar yokEPSS %1emlog · emlog12 Oca 2026
- CVE-2025-6131836İzleyin
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.
KritikCVSS 9,1İstismar yokEPSS %1emlog · emlog8 Ara 2025
- CVE-2021-3008135İzleyin
An issue was discovered in emlog 6.0.0stable.
YüksekCVSS 8,8İstismar yokEPSS %1emlog · emlog24 May 2021
- CVE-2025-4778535İzleyin
EMLOG SQL Injection Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1emlog · emlog15 May 2025
- CVE-2025-4778735İzleyin
Emlog Pro Contains a File Upload Vulnerability
YüksekCVSS 8,9İstismar yokEPSS %1emlog · emlog15 May 2025
- CVE-2018-1831635İzleyin
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
YüksekCVSS 8,8İstismar yokEPSS %1emlog · emlog15 Eki 2018
- CVE-2025-6193035İzleyin
Emlog Pro has CSRF issue that Enables Admin Password Reset
YüksekCVSS 8,8İstismar yokEPSS %0emlog · emlog10 Eki 2025
- CVE-2026-3422834İzleyin
Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write
YüksekCVSS 8,7İstismar yokEPSS %0emlog · emlog3 Nis 2026
- CVE-2020-1902830İzleyin
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/p
YüksekCVSS 7,5İstismar yokEPSS %1emlog · emlog5 Haz 2023
- CVE-2025-3037230İzleyin
Emlog Pro contains an SQL injection vulnerability.
YüksekCVSS 7,7İstismar yokEPSS %1emlog · emlog28 Mar 2025
- CVE-2026-2143330İzleyin
Emlog vulnerable to Server-Side Request Forgery (SSRF)
YüksekCVSS 7,7İstismar yokEPSS %0emlog · emlog2 Oca 2026
- CVE-2023-3912129İzleyin
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
YüksekCVSS 7,2Kavram kanıtıEPSS %3emlog · emlog3 Ağu 2023
- CVE-2025-2582329İzleyin
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a cra
YüksekCVSS 7,3İstismar yokEPSS %0emlog · emlog26 Şub 2025
- CVE-2026-3195429İzleyin
Emlog asynchronous media file deletion missing CSRF protection
YüksekCVSS 7,3İstismar yokEPSS %0emlog · emlog11 Mar 2026
- CVE-2022-4218928İzleyin
Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.
YüksekCVSS 7,2İstismar yokEPSS %2emlog · emlog21 Eki 2022