snow
8 exploits
Active since Nov 2022
Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write
CVSS 6.5
Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypass
CVSS 6.1
emlog < 2022-11-08 - Cross-Site Scripting via tag Parameter in admin/article_save.php
CVSS 3.5
emlog < 2.5.14 - Deserialization of Untrusted Data via Crafted Nickname
CVSS 9.8
emlog < 2.5.10 - Remote Code Execution via Insufficient ZIP Plugin Validation
CVSS 9.8
emlog <= 2.5.22 - Authenticated Stored Cross-Site Scripting via SVG File Upload
CVSS 6.1
emlog 2.5.23 - Improper Authentication via Session Verification Code Reuse
CVSS 9.1
emlog < 2.6.1 - Authenticated Arbitrary File Upload via REST API Endpoint
CVSS 8.8