ZeroHour

CVE-2025-29280

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p19
Published
()
Modified
Description

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.

Vendors
perfree
Products
perfreeblog
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.