CVE-2025-29281: Perfree Perfreeblog

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.

Affected products

  • Perfree Perfreeblog: version 4.0.11 only

Published 2025-04-15. Last modified 2026-06-17.