📦 Perfreeblog

by Perfree

🔍 What is Perfreeblog?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-30333

CRITICAL CVSS 9.8 May 18, 2023

This vulnerability allows attackers to upload malicious files to PerfreeBlog's admin interface, leading to remote code execution. Attackers can gain full control of affected systems by uploading craft...

CVE-2025-60735

HIGH CVSS 7.6 Oct 24, 2025

PerfreeBlog v4.0.11 contains an arbitrary file upload vulnerability in the installPlugin function that allows attackers to upload malicious files. This affects all PerfreeBlog installations running th...

CVE-2025-60730

HIGH CVSS 7.6 Oct 24, 2025

PerfreeBlog v4.0.11 contains an arbitrary file deletion vulnerability in the unInstallTheme function that allows attackers to delete files on the server. This affects all installations of PerfreeBlog ...

CVE-2025-29420

HIGH CVSS 7.5 Aug 25, 2025

PerfreeBlog v4.0.11 contains a directory traversal vulnerability in the getThemeFilesByName function that allows attackers to read arbitrary files on the server. This affects all installations running...

CVE-2025-29281

HIGH CVSS 8.8 Apr 15, 2025

PerfreeBlog 4.0.11 contains an arbitrary file upload vulnerability in the attach component that allows regular users to upload malicious files and execute code. This enables remote code execution (RCE...

CVE-2023-40825

HIGH CVSS 7.2 Aug 28, 2023

This vulnerability allows remote attackers to execute arbitrary code on PerfreeBlog installations by uploading malicious plugin files through the admin interface. It affects all users running PerfreeB...

CVE-2025-60319

MEDIUM CVSS 6.5 Oct 30, 2025

PerfreeBlog v4.0.11 contains a Server-Side Request Forgery vulnerability in the uploadAttachByUrl API endpoint that allows attackers to make unauthorized requests from the server. This could lead to i...

CVE-2025-60729

MEDIUM CVSS 5.3 Oct 24, 2025

PerfreeBlog v4.0.11 contains an arbitrary file read vulnerability in the validThemeFilePath function that allows attackers to read sensitive files on the server. This affects all users running the vul...