← Back

CVE-2025-29280

nvd nist
Published: Apr 15, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.

Affected (1)

Products: Perfree: Perfreeblog
1 product
Perfreeblog
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.0.11

References (2)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.