CVE-2025-61318

CRITICAL

Emlog Pro 2.5.20 - Path Traversal and Arbitrary File Deletion via Admin Template and Plugin Components

Title source: llm
STIX 2.1

Description

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0061
EPSS Percentile 44.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-24
Status published
Products (1)
emlog/emlog 2.5.20
Published Dec 08, 2025
Tracked Since Feb 18, 2026