CVE-2025-62717: Emlog
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.
Affected products
- Emlog Emlog: version 2.5.23 only
Published 2025-10-24. Last modified 2026-06-17.