Stored Cross-Site Scripting Vulnerability in Emlog Website Building System
CVE-2025-47786
What is CVE-2025-47786?
Emlog, a popular open-source website building system, version 2.5.13 is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue allows any registered user to craft malicious JavaScript code that, when executed, causes all website users to inadvertently interact with it. The vulnerability arises from the unvalidated perpage_num
parameter in the /admin/comment.php
script, which is stored directly in the admin_commend_perpage_num
field of the emlog_options
table without adequate filtering. As a result, the malicious code can be rendered on the site, potentially compromising the security of the user's session. Currently, it is undetermined whether a patch has been released to address this critical issue.
Affected Version(s)
emlog = 2.5.13
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved