emlog has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 6.9 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.9
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
emlog vulnerabilities
CVEs affecting emlog, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-53758High· 8.7PoCEmlog is an open source website building system
Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML including <script> tags embedded in Markdown is passed through unes…
CVE-2026-73848Medium· 6.9Emlog is an open source website building system
Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslas…
CVE-2026-53757Medium· 6.9Emlog is an open source website building system
Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's…
CVE-2026-53756Medium· 4.9PoCEmlog is an open source website building system
Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filt…