Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
emlog emlog vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv2
CVE-2019-17073
emlog up to and including 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
Emlog Emlog 6.0.0
Emlog Emlog
7.5
CVSSv2
CVE-2019-16868
emlog up to and including 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.
Emlog Emlog 6.0.0
Emlog Emlog
7.5
CVSSv2
CVE-2021-31737
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
Emlog Emlog 5.3.1
Emlog Emlog 6.0.0
NA
CVE-2022-3968
A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/article_save.php. The manipulation of the argument tag leads to cross site scripting. The attack can be launched remotely. The name ...
Emlog Emlog
3.5
CVSSv2
CVE-2022-1526
A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The manipulation with the input <script>alert(1);</script> leads to cross site scripting. It is possible to initiate the att...
Emlog Emlog
4.3
CVSSv2
CVE-2021-44584
Cross-site scripting (XSS) vulnerability in index.php in emlog version <= pro-1.0.7 allows remote malicious users to inject arbitrary web script or HTML via the s parameter.
Emlog Emlog
NA
CVE-2023-43291
Deserialization of Untrusted Data in emlog pro v.2.1.15 and previous versions allows a remote malicious user to execute arbitrary code via the cache.php component.
Emlog Emlog
NA
CVE-2023-44973
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows malicious users to execute arbitrary code via uploading a crafted PHP file.
Emlog Emlog 2.2.0
NA
CVE-2023-44974
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows malicious users to execute arbitrary code via uploading a crafted PHP file.
Emlog Emlog 2.2.0
1 Github repository
NA
CVE-2023-30338
Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Article Title or Article Summary parameters.
Emlog Emlog 2.0.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-0044
client side
CVE-2021-47601
deserialization
CVE-2024-34994
encryption
CVE-2021-47609
CVE-2024-37079
CVE-2024-38608
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »