Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Perfreeblog MEDIUM 6.5
CVE-2025-60319

PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachCo…

Patch available
Fix from $1,600 2025-10-30
Perfreeblog HIGH 7.6
CVE-2025-60731

PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function

Mitigation only
Fix from $1,950 2025-10-24
Perfreeblog HIGH 7.6
CVE-2025-60735

PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function

Mitigation only
Fix from $1,950 2025-10-24
Perfreeblog HIGH 7.6
CVE-2025-60730

PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function

No fix yet
Fix from $1,950 2025-10-24
Perfreeblog MEDIUM 5.3
CVE-2025-60729

PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function

No fix yet
Fix from $1,600 2025-10-24
Perfreeblog HIGH 7.5
CVE-2025-29420

PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.

No fix yet
Fix from $1,950 2025-08-25
Perfreeblog HIGH 7.5
CVE-2025-29421

PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.

No fix yet
Fix from $1,950 2025-08-25
Perfreeblog HIGH 8.1
CVE-2025-5164

A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component …

No fix yet
Fix from $1,950 2025-05-26
Perfreeblog HIGH 8.8
CVE-2025-29281

In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files an…

No fix yet
Fix from $1,950 2025-04-15
Perfreeblog HIGH 7.2
CVE-2023-40825

An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.

No fix yet
Fix from $1,950 2023-08-28
Perfreeblog CRITICAL 9.8
CVE-2023-30333

An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code …

No fix yet
Fix from $2,300 2023-05-18
Perfreeblog MEDIUM 5.4
CVE-2023-29643

Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.

No fix yet
Fix from $1,600 2023-05-01
Perfreeblog CRITICAL 9.8
CVE-2023-27757

An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a …

No fix yet
Fix from $2,300 2023-03-15