Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code into siteurl parameter resulting in Stored XSS. When someone clicks on the link the malicious code is executed. As of time of publication, no known patched versions exist.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 18 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Emlog
Emlog emlog |
|
CPEs | cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:* | |
Vendors & Products |
Emlog
Emlog emlog |
Wed, 16 Jul 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog before the pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code into siteurl parameter resulting in Stored XSS. When someone clicks on the link the malicious code is executed. As of time of publication, no known patched versions exist. | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code into siteurl parameter resulting in Stored XSS. When someone clicks on the link the malicious code is executed. As of time of publication, no known patched versions exist. |
Wed, 16 Jul 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog before the pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the siteurl parameter. It is possible to inject malicious code into siteurl parameter resulting in Stored XSS. When someone clicks on the link the malicious code is executed. As of time of publication, no known patched versions exist. | |
Title | Emlog vulnerable to stored Cross-site Scripting in links functionality | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-16T13:55:57.980Z
Updated: 2025-07-18T14:52:56.399Z
Reserved: 2025-07-14T17:23:35.258Z
Link: CVE-2025-53924

Updated: 2025-07-18T14:52:47.881Z

Status : Modified
Published: 2025-07-16T14:15:28.700
Modified: 2025-07-18T15:15:28.520
Link: CVE-2025-53924

No data.