CVE-2026-34607: Emlog

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting ZIP archives (plugin/template uploads, backup imports), the function calls $zip->extractTo($path) without sanitizing ZIP entry names. An authenticated admin can upload a crafted ZIP containing entries with ../ sequences to write arbitrary files to the server filesystem, including PHP webshells, achieving Remote Code Execution (RCE). At time of publication, there are no publicly available patches.

Affected products

  • Emlog Emlog: up to and including 2.6.2

Published 2026-04-03. Last modified 2026-07-24.