Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32296 | A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/setting.php?action=mail, which allows administrators to input HTML code that is not properly sanitized, leading to persistent JavaScript execution. |
Wed, 08 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:emlog:emlog:2.5.19:*:*:*:pro:*:*:* |
Mon, 06 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Emlog
Emlog emlog Emlog Pro Project Emlog Pro Project emlog Pro |
|
| Vendors & Products |
Emlog
Emlog emlog Emlog Pro Project Emlog Pro Project emlog Pro |
Fri, 03 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 03 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/setting.php?action=mail, which allows administrators to input HTML code that is not properly sanitized, leading to persistent JavaScript execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-15T13:42:24.484Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60447
Updated: 2025-10-03T14:40:50.518Z
Status : Analyzed
Published: 2025-10-03T14:15:46.150
Modified: 2025-10-08T15:25:42.620
Link: CVE-2025-60447
No data.
OpenCVE Enrichment
Updated: 2025-10-06T14:43:09Z
EUVD