PT-2025-40460 · Emlog · Emlog

·

CVE-2025-61597

·

Published

2025-10-03

·

Updated

2025-10-20

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Emlog versions 2.5.21 and below
Description Emlog is a website building system. A flaw exists where a malicious payload can be saved through the mail template settings, leading to stored cross-site scripting (XSS). When an attacker saves malicious code, any subsequent visit to the settings page by an authenticated administrator will execute attacker-controlled JavaScript. This can result in session or token theft and complete admin account takeover.
Recommendations Update to version 2.5.22 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61597
GHSA-HJ97-HP2C-6M4M

Affected Products

Emlog