CVE-2025-61597

HIGH

Emlog <2.5.22 - XSS

Title source: llm
STIX 2.1

Description

Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored cross‑site scripting (XSS) via the mail template settings. Once a malicious payload is saved, any subsequent visit to the settings page in an authenticated admin context will execute attacker‑controlled JavaScript, enabling session/token theft and full admin account takeover. This issue is fixed in version 2.5.22.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://github.com/emlog/emlog/security/advisories/GHSA-hj97-hp2c-6m4m

Scores

CVSS v3 7.6
EPSS 0.0004
EPSS Percentile 11.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
emlog/emlog < 2.5.19
Published Oct 03, 2025
Tracked Since Feb 18, 2026