Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-60319 PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachCo… Perfreeblog Patch available Fix from $1,6002025-10-30 HIGH 7.6 CVE-2025-60731 PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function Perfreeblog Mitigation only Fix from $1,9502025-10-24 HIGH 7.6 CVE-2025-60735 PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function Perfreeblog Mitigation only Fix from $1,9502025-10-24 HIGH 7.6 CVE-2025-60730 PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function Perfreeblog No fix yet Fix from $1,9502025-10-24 MEDIUM 5.3 CVE-2025-60729 PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function Perfreeblog No fix yet Fix from $1,6002025-10-24 HIGH 7.5 CVE-2025-29420 PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function. Perfreeblog No fix yet Fix from $1,9502025-08-25 HIGH 7.5 CVE-2025-29421 PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function. Perfreeblog No fix yet Fix from $1,9502025-08-25 HIGH 8.1 CVE-2025-5164 A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component … Perfreeblog No fix yet Fix from $1,9502025-05-26 HIGH 8.8 CVE-2025-29281 In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files an… Perfreeblog No fix yet Fix from $1,9502025-04-15 HIGH 7.2 CVE-2023-40825 An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list. Perfreeblog No fix yet Fix from $1,9502023-08-28 CRITICAL 9.8 CVE-2023-30333 An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code … Perfreeblog No fix yet Fix from $2,3002023-05-18 MEDIUM 5.4 CVE-2023-29643 Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function. Perfreeblog No fix yet Fix from $1,6002023-05-01 CRITICAL 9.8 CVE-2023-27757 An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a … Perfreeblog No fix yet Fix from $2,3002023-03-15