CVE-2025-29281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
15/04/2025
Last modified:
24/06/2025

Description

In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools