Report: Latest: CVE-2026-34607 - Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE
CVE ID :CVE-2026-34607 Published : April 3, 2026, 11:17 p.m. | 39 minutes ago Description :Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting ZIP archives (plugin/template uploads, backup imports), the function calls $zip->extractTo($path) without sanitizing ZIP entry names. An authenticated admin can upload a crafted ZIP containing entries with ../ sequences to write arbitrary files to the server filesystem, including PHP webshells, achieving Remote Code Execution (RCE). At time of publication, there are no publicly available patches. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...