CVE-2025-29280

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.
CVSS

No CVSS.

References
Link Resource
https://github.com/Cray0nLee/CVE/issues/1 Exploit Third Party Advisory
https://github.com/Cray0nLee/CVE/issues/1 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*

History

24 Jun 2025, 15:19

Type Values Removed Values Added
References () https://github.com/Cray0nLee/CVE/issues/1 - () https://github.com/Cray0nLee/CVE/issues/1 - Exploit, Third Party Advisory
First Time Perfree
Perfree perfreeblog
CPE cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*

15 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 14:15

Updated : 2025-06-24 15:19


NVD link : CVE-2025-29280

Mitre link : CVE-2025-29280


JSON object : View

Products Affected

perfree

  • perfreeblog
CWE

No CWE.