dengxmenglihua/cve

dengxmenglihua/cve

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
7.6 HIGH

PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function

7.6 HIGH

PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function

5.3 MEDIUM

PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function

7.6 HIGH

PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function

9.8 CRITICAL

zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.