Cross-Site Scripting Vulnerability in Emlog Website Builder by Emlog
CVE-2025-53925

5.4MEDIUM

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
16 July 2025

What is CVE-2025-53925?

Emlog, a popular open source website building system, contains a cross-site scripting (XSS) vulnerability in versions up to and including pro-2.5.17. This flaw allows authenticated remote attackers to upload an SVG file containing malicious JavaScript code through the file upload functionality. When this file is processed by the application, it can lead to the execution of arbitrary web scripts, posing significant risks to the security of the affected websites. As of the last update, there are no known patched versions available, making it crucial for users to review their security practices.

Affected Version(s)

emlog <= pro-2.5.17

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53925 : Cross-Site Scripting Vulnerability in Emlog Website Builder by Emlog