VendorsPerfreeperfreeblogall versions
Vulnerabilities

Perfree PerfreeBlog

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2023-27757
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file.
Published 2023-03-15 · Modified
9.8EPSS 0.009
CVE-2023-30333
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.
Published 2023-05-18 · Modified
9.8EPSS 0.009
CVE-2025-29281
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.
Published 2025-04-15 · Analyzed
8.8EPSS 0.008
CVE-2025-5164
PerfreeBlog JWT JwtUtil hard-coded key
Published 2025-05-26 · Analyzed
8.1EPSS 0.007
CVE-2025-60730
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
Published 2025-10-24 · Modified
7.6EPSS 0.003
CVE-2025-60731
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
Published 2025-10-24 · Modified
7.6EPSS 0.003
CVE-2025-60735
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
Published 2025-10-24 · Modified
7.6EPSS 0.003
CVE-2025-29420
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
Published 2025-08-25 · Analyzed
7.5EPSS 0.009
CVE-2025-29421
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
Published 2025-08-25 · Analyzed
7.5EPSS 0.004
CVE-2023-40825
An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.
Published 2023-08-28 · Modified
7.2EPSS 0.012
CVE-2025-60319
PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java).
Published 2025-10-30 · Analyzed
6.5EPSS 0.002
CVE-2023-29643
Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.
Published 2023-05-01 · Modified
5.4EPSS 0.005
CVE-2025-60729
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
Published 2025-10-24 · Modified
5.3EPSS 0.003
CVE-2025-29280
Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.
Published 2025-04-15 · Analyzed
4.8EPSS 0.003