Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2025-60319
PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachCo…
Perfreeblog
Patch available
HIGH 7.6
CVE-2025-60731
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
Perfreeblog
Mitigation only
HIGH 7.6
CVE-2025-60735
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
Perfreeblog
Mitigation only
HIGH 7.6
CVE-2025-60730
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
Perfreeblog
No fix yet
MEDIUM 5.3
CVE-2025-60729
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
Perfreeblog
No fix yet
HIGH 7.5
CVE-2025-29420
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
Perfreeblog
No fix yet
HIGH 7.5
CVE-2025-29421
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
Perfreeblog
No fix yet
HIGH 8.1
CVE-2025-5164
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component …
Perfreeblog
No fix yet
HIGH 8.8
CVE-2025-29281
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files an…
Perfreeblog
No fix yet
HIGH 7.2
CVE-2023-40825
An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.
Perfreeblog
No fix yet
CRITICAL 9.8
CVE-2023-30333
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code …
Perfreeblog
No fix yet
MEDIUM 5.4
CVE-2023-29643
Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.
Perfreeblog
No fix yet
CRITICAL 9.8
CVE-2023-27757
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a …
Perfreeblog
No fix yet