Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-41517
Published:May 08, 2026
Updated:August 06, 2026
Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. This issue has been patched in version 2.6.11.
Affected Packages
https://github.com/emlog/emlog.git (GITHUB):
Affected version(s) >=pro-2.6.1 <pro-2.6.11
Fix Suggestion:
Update to version pro-2.6.11
Do you need more information?
Contact Us
Weakness Type (CWE)
Unrestricted Upload of File with Dangerous Type
EPSS
Base Score:
0.28