CVE 6.1 MEDIUM

Emlog has Stored Cross-site Scripting vulnerability due to error_CVE-2025-53926

6.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requires the victim to send POST requests, therefore the victim must be persuaded into clicking into sent URL. As of time of publication, no known patched versions exist.

Basic Information

ID CVE-2025-53926
Source GitHub_M
Published Jul 16, 2025 at 15:37
Modified Jul 16, 2025 at 15:55

Affected Product

Vendor emlog
Product emlog
Version <= pro-2.5.17
Affected Versions emlog emlog <= pro-2.5.17

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.