CVE-2025-29280
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2025-29280 is a stored cross-site scripting (XSS) vulnerability affecting PerfreeBlog v4.0.11. An attacker can exploit this flaw by injecting malicious code into the website name field of the backend system settings interface. Once executed, the code can steal user data, modify content, or even take control of affected users' accounts. This issue poses a significant risk, particularly for users who have not applied the necessary security patches. It is strongly recommended that users update their PerfreeBlog installations to a secure version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.