Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-62166 FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is … Freshrss 1.28.0+ Fix from $1,9502026-03-09 CRITICAL 9.8 CVE-2025-68932 FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() a… Freshrss 1.28.0+ Fix from $2,3002025-12-27 HIGH 7.5 CVE-2025-68148 FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy mod… Freshrss 1.28.0+ Fix from $1,9502025-12-27 MEDIUM 6.5 CVE-2025-59949 FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to de… Freshrss 1.27.1+ Fix from $1,6002025-12-18 HIGH 8.8 CVE-2025-58173 FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration par… Freshrss 1.27.1+ Fix from $1,9502025-12-16 MEDIUM 5.3 CVE-2025-61586 FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, a… Freshrss 1.27.0+ Fix from $1,6002025-09-30 MEDIUM 5.4 CVE-2025-59950 FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialo… Freshrss 1.27.0+ Fix from $1,6002025-09-30 MEDIUM 5.4 CVE-2025-59948 FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not sanitize certain event handler attributes in feed content, so by f… Freshrss 1.27.0+ Fix from $1,6002025-09-29 CRITICAL 9.8 CVE-2025-54592 FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs ou… Freshrss 1.27.0+ Fix from $2,3002025-09-29 CRITICAL 9.8 CVE-2025-54875 FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker can create a new admin user w… Freshrss 1.27.0+ Fix from $2,3002025-09-29 MEDIUM 6.1 CVE-2025-57769 FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below contain a vulnerability where a specially crafted page can trick a user i… Freshrss 1.27.0+ Fix from $1,6002025-09-29 HIGH 7.5 CVE-2025-54591 FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of default admin users, due to la… Freshrss 1.27.0+ Fix from $1,9502025-09-29 HIGH 7.2 CVE-2025-54593 FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the… Freshrss 1.26.2+ Fix from $1,9502025-08-01 HIGH 7.1 CVE-2025-46341 FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, when the server is using HTTP auth via reverse proxy, it's possible to impers… Freshrss 1.26.2+ Fix from $1,9502025-06-04 MEDIUM 6.7 CVE-2025-32015 FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, HTML is sanitized improperly inside the `<iframe srcdoc>` attribute, which le… Freshrss 1.26.2+ Fix from $1,6002025-06-04 HIGH 7.5 CVE-2025-31134 FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if c… Freshrss 1.26.2+ Fix from $1,9502025-06-04 MEDIUM 5.4 CVE-2025-31136 FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the feeds page. This occurs by c… Freshrss 1.26.2+ Fix from $1,6002025-06-04 MEDIUM 5.5 CVE-2023-22481 FreshRSS is a self-hosted RSS feed aggregator. When using the greader API, the provided password is logged in clear in `users/_/log_api.txt` in the c… Freshrss 1.21.0+ Fix from $1,6002023-03-06 HIGH 7.5 CVE-2022-23497 FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition to user preferences, such co… Freshrss 1.20.2+ Fix from $1,9502022-12-09 MEDIUM 6.1 CVE-2018-19782 Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML … Freshrss No fix yet Fix from $1,6002019-01-30