Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject HTML/JS code into keyword parameter. If one persuades an user into clicking into prepared link it is possible to execute any JS code in admin's browser. As of time of publication, no known patched versions exist.
Metrics
Affected Vendors & Products
References
History
Tue, 22 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 18 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Emlog
Emlog emlog |
|
CPEs | cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:* | |
Vendors & Products |
Emlog
Emlog emlog |
Wed, 16 Jul 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog before the pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject HTML/JS code into keyword parameter. If one persuades an user into clicking into prepared link it is possible to execute any JS code in admin's browser. As of time of publication, no known patched versions exist. | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject HTML/JS code into keyword parameter. If one persuades an user into clicking into prepared link it is possible to execute any JS code in admin's browser. As of time of publication, no known patched versions exist. |
Wed, 16 Jul 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog before the pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is possible to inject HTML/JS code into keyword parameter. If one persuades an user into clicking into prepared link it is possible to execute any JS code in admin's browser. As of time of publication, no known patched versions exist. | |
Title | Emlog vulnerable to reflected Cross-site Scripting in admin panel | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-16T13:53:11.047Z
Updated: 2025-07-22T14:59:08.801Z
Reserved: 2025-07-14T17:23:35.258Z
Link: CVE-2025-53923

Updated: 2025-07-22T14:58:57.312Z

Status : Modified
Published: 2025-07-16T14:15:28.530
Modified: 2025-07-22T15:15:37.520
Link: CVE-2025-53923

No data.