Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.26% | — | Perfreeblog | 30/10/2025 | 17/6/2026 | PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java). | |
| Modificada | Alta (7.6) | 0.27% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function | |
| Modificada | Alta (7.6) | 0.27% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function | |
| Modificada | Alta (7.6) | 0.29% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function | |
| Modificada | Media (5.3) | 0.32% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function | |
| Analizada | Alta (7.5) | 0.36% | — | Perfreeblog | 25/8/2025 | 17/6/2026 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function. | |
| Analizada | Alta (7.5) | 0.91% | — | Perfreeblog | 25/8/2025 | 17/6/2026 | PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function. | |
| Analizada | Media (6.3) | 0.74% | — | Perfreeblog | 26/5/2025 | 17/6/2026 | A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The… | |
| Analizada | Alta (8.8) | 0.75% | — | Perfreeblog | 15/4/2025 | 17/6/2026 | In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them. | |
| Analizada | Media (4.8) | 0.27% | — | Perfreeblog | 15/4/2025 | 17/6/2026 | Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code. | |
| Modificada | Alta (7.2) | 1.2% | — | Perfreeblog | 28/8/2023 | 17/6/2026 | An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list. | |
| Modificada | Crítica (9.8) | 0.94% | — | Perfreeblog | 18/5/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (5.4) | 0.46% | — | Perfreeblog | 1/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function. | |
| Modificada | Crítica (9.8) | 0.94% | — | Perfreeblog | 15/3/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file. |