VendorsPerfreeperfreeblog3.1.2
Vulnerabilities

Perfree PerfreeBlog 3.1.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-30333
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.
Published 2023-05-18 · Modified
9.8EPSS 0.009
CVE-2023-40825
An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.
Published 2023-08-28 · Modified
7.2EPSS 0.012
CVE-2023-29643
Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.
Published 2023-05-01 · Modified
5.4EPSS 0.005