Cross-Site Scripting Vulnerability in Emlog Web Building System
CVE-2025-53926
6.1MEDIUM
What is CVE-2025-53926?
Emlog, an open-source website building system, features a cross-site scripting vulnerability that allows remote attackers to inject arbitrary web scripts or HTML into affected installations. This vulnerability affects Emlog versions up to and including Pro 2.5.17 and can be exploited through manipulation of the comment and comname parameters. Attackers can leverage reflected XSS attacks, which require victims to be tricked into sending POST requests. As of the latest information, no patched versions are available to mitigate this vulnerability.
Affected Version(s)
emlog <= pro-2.5.17