« Volver al listado

Perfree

Perfreeblog: vulnerabilidades y CVE

Perfreeblog tiene 14 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE14
Últimos 12 meses5
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-60319Media (6.5)0.26%—30 oct 2025
PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java).
CVE-2025-60735Alta (7.6)0.27%—24 oct 2025
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
CVE-2025-60731Alta (7.6)0.27%—24 oct 2025
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
CVE-2025-60730Alta (7.6)0.29%—24 oct 2025
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
CVE-2025-60729Media (5.3)0.32%—24 oct 2025
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
CVE-2025-29421Alta (7.5)0.36%—25 ago 2025
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
CVE-2025-29420Alta (7.5)0.91%—25 ago 2025
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
CVE-2025-5164Media (6.3)0.74%—26 may 2025
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic…
CVE-2025-29281Alta (8.8)0.75%—15 abr 2025
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.
CVE-2025-29280Media (4.8)0.27%—15 abr 2025
Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.
CVE-2023-40825Alta (7.2)1.2%—28 ago 2023
An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.
CVE-2023-30333Crítica (9.8)0.94%—18 may 2023
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.
CVE-2023-29643Media (5.4)0.46%—1 may 2023
Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.
CVE-2023-27757Crítica (9.8)0.94%—15 mar 2023
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services3
  2. T1005 Data from Local System2
  3. T1190 Exploit Public-Facing Application2
  4. T1505.003 Web Shell2
  5. T1059 Command and Scripting Interpreter1
  6. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Perfree