CVE-2025-61318

CRITICAL

Emlog Pro 2.5.20 - Path Traversal

Title source: llm
STIX 2.1

Description

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

Scores

CVSS v3 9.1
EPSS 0.0137
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-24
Status published
Products (1)
emlog/emlog 2.5.20
Published Dec 08, 2025
Tracked Since Feb 18, 2026