CVE-2025-53926

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requires the victim to send POST requests, therefore the victim must be persuaded into clicking into sent URL. As of time of publication, no known patched versions exist.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:*

History

14 Aug 2025, 20:37

Type Values Removed Values Added
References () https://github.com/emlog/emlog/security/advisories/GHSA-g8jx-pj5p-fm3x - () https://github.com/emlog/emlog/security/advisories/GHSA-g8jx-pj5p-fm3x - Exploit, Vendor Advisory
CPE cpe:2.3:a:emlog:emlog:*:*:*:*:pro:*:*:*
First Time Emlog emlog
Emlog

16 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-16 16:15

Updated : 2025-08-14 20:37


NVD link : CVE-2025-53926

Mitre link : CVE-2025-53926


JSON object : View

Products Affected

emlog

  • emlog
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')