CVE-2025-29281
PoC —CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
Description
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.
- Vendors
- perfree
- Products
- perfreeblog
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.