PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
CVSS Metrics