perfree kayıtları
perfree üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-320 Key Management Errors1
- CWE-459 Incomplete Cleanup1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-27757İstismar yok | An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary coperfree · perfreeblog · CWE-434 | Kritik9,8 | — | %0,9 | 14 Mar 2023 |
39İzleyin | CVE-2023-30333İstismar yok | An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrperfree · perfreeblog · CWE-434 | Kritik9,8 | — | %0,9 | 18 May 2023 |
35İzleyin | CVE-2025-29281İstismar yok | In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitraryperfree · perfreeblog · CWE-94 | Yüksek8,8 | — | %0,8 | 15 Nis 2025 |
30İzleyin | CVE-2025-29420İstismar yok | PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.perfree · perfreeblog · CWE-22 | Yüksek7,5 | — | %0,9 | 25 Ağu 2025 |
30İzleyin | CVE-2025-29421İstismar yok | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.perfree · perfreeblog · CWE-284 | Yüksek7,5 | — | %0,4 | 25 Ağu 2025 |
30İzleyin | CVE-2025-60730İstismar yok | PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme functionperfree · perfreeblog · CWE-459 | Yüksek7,6 | — | %0,3 | 24 Eki 2025 |
30İzleyin | CVE-2025-60735İstismar yok | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin functionperfree · perfreeblog · CWE-434 | Yüksek7,6 | — | %0,3 | 24 Eki 2025 |
30İzleyin | CVE-2025-60731İstismar yok | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme functionperfree · perfreeblog · CWE-434 | Yüksek7,6 | — | %0,3 | 24 Eki 2025 |
28İzleyin | CVE-2023-40825İstismar yok | An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/perfree · perfreeblog · CWE-434 | Yüksek7,2 | — | %1,2 | 28 Ağu 2023 |
26İzleyin | CVE-2025-60319İstismar yok | PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint perfree · perfreeblog · CWE-918 | Orta6,5 | — | %0,2 | 30 Eki 2025 |
25İzleyin | CVE-2025-5164İstismar yok | PerfreeBlog JWT JwtUtil hard-coded keyperfree · perfreeblog · CWE-320 | Orta6,3 | — | %0,7 | 25 May 2025 |
21İzleyin | CVE-2023-29643İstismar yok | Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.perfree · perfreeblog · CWE-79 | Orta5,4 | — | %0,5 | 1 May 2023 |
21İzleyin | CVE-2025-60729İstismar yok | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath functionperfree · perfreeblog · CWE-126 | Orta5,3 | — | %0,3 | 24 Eki 2025 |
19İzleyin | CVE-2025-29280İstismar yok | Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface aperfree · perfreeblog · CWE-79 | Orta4,8 | — | %0,3 | 15 Nis 2025 |
- CVE-2023-2775739İzleyin
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary co
KritikCVSS 9,8İstismar yokEPSS %1perfree · perfreeblog14 Mar 2023
- CVE-2023-3033339İzleyin
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitr
KritikCVSS 9,8İstismar yokEPSS %1perfree · perfreeblog18 May 2023
- CVE-2025-2928135İzleyin
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary
YüksekCVSS 8,8İstismar yokEPSS %1perfree · perfreeblog15 Nis 2025
- CVE-2025-2942030İzleyin
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
YüksekCVSS 7,5İstismar yokEPSS %1perfree · perfreeblog25 Ağu 2025
- CVE-2025-2942130İzleyin
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
YüksekCVSS 7,5İstismar yokEPSS %0perfree · perfreeblog25 Ağu 2025
- CVE-2025-6073030İzleyin
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
YüksekCVSS 7,6İstismar yokEPSS %0perfree · perfreeblog24 Eki 2025
- CVE-2025-6073530İzleyin
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
YüksekCVSS 7,6İstismar yokEPSS %0perfree · perfreeblog24 Eki 2025
- CVE-2025-6073130İzleyin
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
YüksekCVSS 7,6İstismar yokEPSS %0perfree · perfreeblog24 Eki 2025
- CVE-2023-4082528İzleyin
An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/
YüksekCVSS 7,2İstismar yokEPSS %1perfree · perfreeblog28 Ağu 2023
- CVE-2025-6031926İzleyin
PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint
OrtaCVSS 6,5İstismar yokEPSS %0perfree · perfreeblog30 Eki 2025
- CVE-2025-516425İzleyin
PerfreeBlog JWT JwtUtil hard-coded key
OrtaCVSS 6,3İstismar yokEPSS %1perfree · perfreeblog25 May 2025
- CVE-2023-2964321İzleyin
Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.
OrtaCVSS 5,4İstismar yokEPSS %0perfree · perfreeblog1 May 2023
- CVE-2025-6072921İzleyin
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
OrtaCVSS 5,3İstismar yokEPSS %0perfree · perfreeblog24 Eki 2025
- CVE-2025-2928019İzleyin
Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface a
OrtaCVSS 4,8İstismar yokEPSS %0perfree · perfreeblog15 Nis 2025