CVE-2025-60447
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/setting.php?action=mail, which allows administrators to input HTML code that is not properly sanitized, leading to persistent JavaScript execution.
- Affected products
- Emlog Pro
- Emlog
- = 2.5.19
- Fix
- Available
- CVSS 3.1
- 5.9 MEDIUM
- EPSS
- 0.2% (15th percentile)
- Weakness
- CWE-79
- NVD status
- Analyzed
- Published
- 2025-10-03
CVE-2025-60447 at NVD
No indexed exploits for CVE-2025-60447 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-60447 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.