İçeriğe atla
Noroxi

perfree kayıtları

perfree üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2023-27757
    39İzleyin

    An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary co

    KritikCVSS 9,8İstismar yokEPSS %1

    perfree · perfreeblog14 Mar 2023

  • CVE-2023-30333
    39İzleyin

    An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitr

    KritikCVSS 9,8İstismar yokEPSS %1

    perfree · perfreeblog18 May 2023

  • CVE-2025-29281
    35İzleyin

    In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary

    YüksekCVSS 8,8İstismar yokEPSS %1

    perfree · perfreeblog15 Nis 2025

  • CVE-2025-29420
    30İzleyin

    PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.

    YüksekCVSS 7,5İstismar yokEPSS %1

    perfree · perfreeblog25 Ağu 2025

  • CVE-2025-29421
    30İzleyin

    PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.

    YüksekCVSS 7,5İstismar yokEPSS %0

    perfree · perfreeblog25 Ağu 2025

  • CVE-2025-60730
    30İzleyin

    PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function

    YüksekCVSS 7,6İstismar yokEPSS %0

    perfree · perfreeblog24 Eki 2025

  • CVE-2025-60735
    30İzleyin

    PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function

    YüksekCVSS 7,6İstismar yokEPSS %0

    perfree · perfreeblog24 Eki 2025

  • CVE-2025-60731
    30İzleyin

    PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function

    YüksekCVSS 7,6İstismar yokEPSS %0

    perfree · perfreeblog24 Eki 2025

  • CVE-2023-40825
    28İzleyin

    An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/

    YüksekCVSS 7,2İstismar yokEPSS %1

    perfree · perfreeblog28 Ağu 2023

  • CVE-2025-60319
    26İzleyin

    PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint

    OrtaCVSS 6,5İstismar yokEPSS %0

    perfree · perfreeblog30 Eki 2025

  • CVE-2025-5164
    25İzleyin

    PerfreeBlog JWT JwtUtil hard-coded key

    OrtaCVSS 6,3İstismar yokEPSS %1

    perfree · perfreeblog25 May 2025

  • CVE-2023-29643
    21İzleyin

    Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.

    OrtaCVSS 5,4İstismar yokEPSS %0

    perfree · perfreeblog1 May 2023

  • CVE-2025-60729
    21İzleyin

    PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function

    OrtaCVSS 5,3İstismar yokEPSS %0

    perfree · perfreeblog24 Eki 2025

  • CVE-2025-29280
    19İzleyin

    Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface a

    OrtaCVSS 4,8İstismar yokEPSS %0

    perfree · perfreeblog15 Nis 2025