CVE-2025-29280

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.
References
Link Resource
https://github.com/Cray0nLee/CVE/issues/1 Exploit Third Party Advisory
https://github.com/Cray0nLee/CVE/issues/1 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-15 14:15

Updated : 2025-06-24 15:19


NVD link : CVE-2025-29280

Mitre link : CVE-2025-29280

CVE.ORG link : CVE-2025-29280


JSON object : View

Products Affected

perfree

  • perfreeblog
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')