Stored Cross-Site Scripting Vulnerability in Emlog Website Building System
CVE-2025-47786

1.9LOW

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
15 May 2025

What is CVE-2025-47786?

Emlog, a popular open-source website building system, version 2.5.13 is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue allows any registered user to craft malicious JavaScript code that, when executed, causes all website users to inadvertently interact with it. The vulnerability arises from the unvalidated perpage_num parameter in the /admin/comment.php script, which is stored directly in the admin_commend_perpage_num field of the emlog_options table without adequate filtering. As a result, the malicious code can be rendered on the site, potentially compromising the security of the user's session. Currently, it is undetermined whether a patch has been released to address this critical issue.

Affected Version(s)

emlog = 2.5.13

References

CVSS V4

Score:
1.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47786 : Stored Cross-Site Scripting Vulnerability in Emlog Website Building System