Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requires the victim to send POST requests, therefore the victim must be persuaded into clicking into sent URL. As of time of publication, no known patched versions exist.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:* |
Wed, 16 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Jul 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requires the victim to send POST requests, therefore the victim must be persuaded into clicking into sent URL. As of time of publication, no known patched versions exist. | |
Title | Emlog has Stored Cross-site Scripting vulnerability due to error | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-16T15:37:44.789Z
Updated: 2025-07-16T15:55:28.326Z
Reserved: 2025-07-14T17:23:35.258Z
Link: CVE-2025-53926

Updated: 2025-07-16T15:55:19.607Z

Status : Analyzed
Published: 2025-07-16T16:15:27.677
Modified: 2025-08-14T20:37:42.590
Link: CVE-2025-53926

No data.