CVE-2025-29401: Emlog
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Affected products
- Emlog Emlog: version 2.5.7 only
Published 2025-03-19. Last modified 2026-06-17.