CVE-2025-29280

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
15/04/2025
Last modified:
24/06/2025

Description

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*