CVE-2025-62717
Severity CVSS v4.0:
LOW
Type:
CWE-287
Authentication Issues
Publication date:
24/10/2025
Last modified:
28/10/2025
Description
Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.
Impact
Base Score 4.0
2.70
Severity 4.0
LOW
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:emlog:emlog:2.5.23:*:*:*:pro:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



