Emlog is a single, narrowly scoped web-based blogging platform that, despite limited product breadth, occupies a notable position in the vulnerability landscape and skews toward serious outcomes with a meaningful share reaching critical severity. The vulnerability exposure recurs across a consistent set of web-application weakness classes including cross-site scripting, unrestricted file uploads, code injection, SQL injection, and cross-site request forgery, reflecting the input-handling and access-control demands characteristic of server-side content-management systems. These weakness patterns are durable across the platform's lifecycle and suggest persistent challenges in validating and sanitizing user-supplied data and protecting against state-changing requests. Defenders deploying or maintaining Emlog instances should prioritize input validation hardening and restrict administrative access; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Emlog over time
Signals from CVEs in this vendor scope (93 CVEs).
93 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44974CRITICAL An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | Oct 3, 2023 | 9.8 | 37 | NO | NO |
CVE-2021-3293MEDIUM emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file. | Feb 8, 2021 | 5.3 | 37 | NO | YES |
CVE-2021-31737CRITICAL emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php. | May 6, 2021 | 9.8 | 32 | NO | NO |
CVE-2019-16868CRITICAL emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter. | Sep 25, 2019 | 9.8 | 32 | NO | NO |
CVE-2023-39121HIGH emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php. | Aug 3, 2023 | 7.2 | 31 | NO | YES |
CVE-2021-40883CRITICAL A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins. | Dec 14, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-21585CRITICAL Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module. | Apr 2, 2021 | 9.8 | 31 | NO | NO |
CVE-2025-9296CRITICAL A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the | Aug 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-39276HIGH The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZI | May 29, 2026 | 7.2 | 29 | NO | NO |
CVE-2026-22799HIGH Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to imp | Jan 12, 2026 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (93 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Emlog.
Media articles that mention a CVE ID that affects a product developed by Emlog — matched by CVE ID, not by vendor name.