CVE-2026-53757
Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory structure is checked. An attacker can overwrite arbitrary files on the server filesystem, including config.php for immediate RCE. At time of publication, there are no publicly known patches.
| CWE | CWE-22 |
| Vendor | emlog |
| Product | emlog |
| Published | Sep 4, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for emlog emlog
Be the first to know when new unknown vulnerabilities affecting emlog emlog are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
emlog / emlog
<= 2.6.29