CVE-2025-61769 - CVE House
Back to Database
Status published Low CVE-2025-61769

Emlog vulnerable to stored XSS in file upload functionality in emlog

Vulnerability Description

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authenticated user it is possible to upload .svg file that contains JavaScript code that is later being executed. Commit 052f9c4226b2c0014bcd857fec47677340b185b1 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-61769

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

emlog
Vulnerable Versions:
<= 2.5.22

Timeline

Official Publish: October 6th, 2025
Last Modified: October 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)