CVEs (14)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java). |
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function |
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function |
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function |
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function |
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function. |
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function. |
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic...Show more |
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them. |
Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code. |
An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list. |
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file. |
Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function. |
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file. |