Path traversal in Emlog Pro - CVE-2026-53757
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to path traversal in the emUnZip() ZIP extraction function when processing uploaded plugin or template ZIP archives. A remote user can upload a specially crafted ZIP archive containing traversal entries to execute arbitrary code.
Exploitation requires access to the administrative plugin, template upload, or store update functionality, and exploitation was confirmed on PHP 7.x and early PHP 8.0.x releases.