Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Emlog
Emlog emlog |
|
| Vendors & Products |
Emlog
Emlog emlog |
Fri, 04 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory structure is checked. An attacker can overwrite arbitrary files on the server filesystem, including config.php for immediate RCE. At time of publication, there are no publicly known patches. | |
| Title | Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-04T17:47:38.864Z
Reserved: 2026-06-10T17:48:40.546Z
Link: CVE-2026-53757
No data.
Status : Received
Published: 2026-09-04T18:17:52.500
Modified: 2026-09-04T18:17:52.500
Link: CVE-2026-53757
No data.
OpenCVE Enrichment
Updated: 2026-09-04T21:30:07Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')