Stored Cross-Site Scripting Vulnerability in Emlog Website Building System
CVE-2025-47786
What is CVE-2025-47786?
Emlog, a popular open-source website building system, version 2.5.13 is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue allows any registered user to craft malicious JavaScript code that, when executed, causes all website users to inadvertently interact with it. The vulnerability arises from the unvalidated perpage_num parameter in the /admin/comment.php script, which is stored directly in the admin_commend_perpage_num field of the emlog_options table without adequate filtering. As a result, the malicious code can be rendered on the site, potentially compromising the security of the user's session. Currently, it is undetermined whether a patch has been released to address this critical issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
emlog = 2.5.13
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
