CVE-2025-47787

CRITICAL

Emlog < 2.5.10 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP plugin files. This insufficient validation allows attackers to execute arbitrary code on the vulnerable system. Version 2.5.10 contains a patch for the issue.

Scores

CVSS v3 9.8
EPSS 0.0180
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
emlog/emlog < 2.5.10
Published May 15, 2025
Tracked Since Feb 18, 2026