CVE-2025-29280

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-29280
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29280.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-29280
Published
2025-04-15T14:15:41Z
Modified
2025-06-27T11:04:25.302804Z
Summary
[none]
Details

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.

References

Affected packages

Git / github.com/perfree/perfreeblog

Affected ranges

Type
GIT
Repo
https://github.com/perfree/perfreeblog
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

V1.*

V1.0.0
V1.0.0-Beta
V1.0.1-Beta
V1.0.3
V1.1.0
V1.2.0
V1.2.1
V1.2.2

v1.*

v1.0.1
v1.0.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.3.0
v1.3.1
v1.3.2

v2.*

v2.0.0
v2.1.0
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1

v3.*

v3.0.0
v3.1.0
v3.1.1
v3.1.2

v4.*

v4.0.0
v4.0.0-beta.1.01
v4.0.1
v4.0.11