Cross-Site Scripting Vulnerability in Emlog Web Building System
CVE-2025-53926

6.1MEDIUM

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
16 July 2025

What is CVE-2025-53926?

Emlog, an open-source website building system, features a cross-site scripting vulnerability that allows remote attackers to inject arbitrary web scripts or HTML into affected installations. This vulnerability affects Emlog versions up to and including Pro 2.5.17 and can be exploited through manipulation of the comment and comname parameters. Attackers can leverage reflected XSS attacks, which require victims to be tricked into sending POST requests. As of the latest information, no patched versions are available to mitigate this vulnerability.

Affected Version(s)

emlog <= pro-2.5.17

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53926 : Cross-Site Scripting Vulnerability in Emlog Web Building System