CVE-2023-44974: Emlog

Critical severity, CVSS 9.8. EPSS: 20.4% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Affected products

  • Emlog Emlog: version 2.2.0 only

Published 2023-10-03. Last modified 2026-06-17.