VendorsELOG Projectelogall versions
Vulnerabilities

ELOG Project ELOG

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2025-64349
ELOG user profile missing authorization
Published 2025-10-31 · Analyzed
8.8EPSS 0.004
CVE-2025-62618
ELOG file upload stored XSS
Published 2025-10-31 · Analyzed
8.6EPSS 0.003
CVE-2019-3993
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP POST request.
Published 2019-12-17 · Modified
7.5EPSS 0.457
CVE-2019-3995
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request.
Published 2019-12-17 · Modified
7.5EPSS 0.285
CVE-2019-3996
ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.
Published 2019-12-17 · Modified
7.5EPSS 0.059
CVE-2019-3994
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multiple HTTP POST requests which causes the ELOG function retrieve_url() to use a freed variable.
Published 2019-12-17 · Modified
7.5EPSS 0.029
CVE-2019-3992
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames and, in older versions of ELOG, passwords.
Published 2019-12-17 · Modified
7.5EPSS 0.013
CVE-2016-6342
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
Published 2017-06-27 · Modified
7.5EPSS 0.010
CVE-2025-64348
ELOG configuration file authorization bypass
Published 2025-10-31 · Modified
7.1EPSS 0.003