Home

Description

Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. This issue has been patched in version 2.6.11.

PUBLISHED Reserved 2026-04-20 | Published 2026-05-08 | Updated 2026-05-08 | Assigner GitHub_M

Problem types

CWE-434: Unrestricted Upload of File with Dangerous Type

Product status

< 2.6.11
affected

References

github.com/.../emlog/security/advisories/GHSA-8qwx-6jx6-94x4

cve.org (CVE-2026-41517)

nvd.nist.gov (CVE-2026-41517)

Download JSON