CVE-2025-61318: Emlog

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

Affected products

  • Emlog Emlog: version 2.5.20 only

Published 2025-12-08. Last modified 2026-06-17.