Cross-Site Scripting Vulnerability in Emlog Website Builder by Emlog
CVE-2025-53925
5.4MEDIUM
What is CVE-2025-53925?
Emlog, a popular open source website building system, contains a cross-site scripting (XSS) vulnerability in versions up to and including pro-2.5.17. This flaw allows authenticated remote attackers to upload an SVG file containing malicious JavaScript code through the file upload functionality. When this file is processed by the application, it can lead to the execution of arbitrary web scripts, posing significant risks to the security of the affected websites. As of the last update, there are no known patched versions available, making it crucial for users to review their security practices.
Affected Version(s)
emlog <= pro-2.5.17