CVE-2025-29280

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.
References
Link Resource
https://github.com/Cray0nLee/CVE/issues/1 Exploit Third Party Advisory
https://github.com/Cray0nLee/CVE/issues/1 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*

History

24 Jun 2025, 15:19

Type Values Removed Values Added
CPE cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*
First Time Perfree perfreeblog
Perfree
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Scripting almacenado en PerfreeBlog v4.0.11 en el campo de nombre del sitio web de la interfaz de configuración del sistema backend que permite a un atacante insertar y ejecutar código malicioso arbitrario.
References () https://github.com/Cray0nLee/CVE/issues/1 - () https://github.com/Cray0nLee/CVE/issues/1 - Exploit, Third Party Advisory

15 Apr 2025, 18:15

Type Values Removed Values Added
CWE CWE-79
References () https://github.com/Cray0nLee/CVE/issues/1 - () https://github.com/Cray0nLee/CVE/issues/1 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

15 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 14:15

Updated : 2025-06-24 15:19


NVD link : CVE-2025-29280

Mitre link : CVE-2025-29280

CVE.ORG link : CVE-2025-29280


JSON object : View

Products Affected

perfree

  • perfreeblog
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')