CVE-2025-61769 Details
Description
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is possible to upload .svg file that contains JavaScript code that is later being executed. Commit 052f9c4226b2c0014bcd857fec47677340b185b1 fixes the issue.
A cross-site scripting (XSS) vulnerability has been identified in Emlog versions through 2.5.22. This vulnerability allows authenticated remote attackers to inject arbitrary web scripts or HTML via the file upload feature. The issue arises from the ability to upload .svg files containing JavaScript code, which is subsequently executed. The vulnerability has been addressed by removing .svg files from the list of allowed file types.
Users can update to Emlog version 2.5.23 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/emlog/emlog/security/advisories/GHSA-rrf5-pv68-gpjf | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/emlog/emlog/commit/052f9c4226b2c0014bcd857fec47677340b185b1 | [email protected] | Patch |
| https://github.com/emlog/emlog/security/advisories/GHSA-rrf5-pv68-gpjf | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| emlog emlog | < 2.5.22 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 9, 2025 | Initial Analysis | [email protected] |
| Oct 6, 2025 | CVE Modified | CISA-ADP |
| Oct 6, 2025 | New CVE Received | [email protected] |