CVE-2025-29280

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Apr 15, 2025
CWE ID 79

Summary

CVE-2025-29280 is a stored cross-site scripting (XSS) vulnerability affecting PerfreeBlog v4.0.11. An attacker can exploit this flaw by injecting malicious code into the website name field of the backend system settings interface. Once executed, the code can steal user data, modify content, or even take control of affected users' accounts. This issue poses a significant risk, particularly for users who have not applied the necessary security patches. It is strongly recommended that users update their PerfreeBlog installations to a secure version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share