CVE-2025-68402
- EPSS 0.06%
- Veröffentlicht 09.03.2026 19:41:57
- Zuletzt bearbeitet 11.03.2026 13:53:47
FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 chars to 64. password_verify() is currently being called with a constructed string (SHA-256 nonce + part of a bcrypt hash) instead ...
CVE-2025-62166
- EPSS 0.16%
- Veröffentlicht 09.03.2026 19:35:37
- Zuletzt bearbeitet 13.03.2026 19:39:08
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, an...
CVE-2025-68148
- EPSS 0.02%
- Veröffentlicht 26.12.2025 23:46:53
- Zuletzt bearbeitet 31.12.2025 21:16:56
FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majorit...
CVE-2025-68932
- EPSS 0.04%
- Veröffentlicht 26.12.2025 23:43:34
- Zuletzt bearbeitet 31.12.2025 21:12:56
FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() and uniqid()) to generate remember-me authentication tokens and challenge-response nonces. This allows...
CVE-2025-59949
- EPSS 0.03%
- Veröffentlicht 18.12.2025 18:31:54
- Zuletzt bearbeitet 30.12.2025 19:52:57
FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via <track src>. Version 1.27.1 patches the issue.
CVE-2025-58173
- EPSS 0.16%
- Veröffentlicht 15.12.2025 23:07:25
- Zuletzt bearbeitet 07.01.2026 20:41:09
FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it's possible to call `install.php` and perform various administrative actions as an unprivil...
CVE-2025-61586
- EPSS 0.09%
- Veröffentlicht 30.09.2025 04:44:53
- Zuletzt bearbeitet 03.10.2025 15:39:40
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, allowing attackers to gain additional information about the server by checking if certain directories ...
CVE-2025-59950
- EPSS 0.03%
- Veröffentlicht 30.09.2025 04:43:45
- Zuletzt bearbeitet 03.10.2025 15:52:28
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management p...
CVE-2025-59948
- EPSS 0.03%
- Veröffentlicht 29.09.2025 23:15:32
- Zuletzt bearbeitet 03.10.2025 15:55:15
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not sanitize certain event handler attributes in feed content, so by finding a page that renders feed entries without CSP, it is possible to execute an XSS payload. The Al...
CVE-2025-54592
- EPSS 0.08%
- Veröffentlicht 29.09.2025 22:15:36
- Zuletzt bearbeitet 03.10.2025 16:04:21
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused by an attack...