CVE-2025-68148
- EPSS 0.02%
- Veröffentlicht 26.12.2025 23:46:53
- Zuletzt bearbeitet 31.12.2025 21:16:56
FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majorit...
CVE-2025-68932
- EPSS 0.04%
- Veröffentlicht 26.12.2025 23:43:34
- Zuletzt bearbeitet 31.12.2025 21:12:56
FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() and uniqid()) to generate remember-me authentication tokens and challenge-response nonces. This allows...
CVE-2025-59949
- EPSS 0.03%
- Veröffentlicht 18.12.2025 18:31:54
- Zuletzt bearbeitet 30.12.2025 19:52:57
FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via <track src>. Version 1.27.1 patches the issue.
CVE-2025-58173
- EPSS 0.16%
- Veröffentlicht 15.12.2025 23:07:25
- Zuletzt bearbeitet 07.01.2026 20:41:09
FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it's possible to call `install.php` and perform various administrative actions as an unprivil...
CVE-2025-61586
- EPSS 0.08%
- Veröffentlicht 30.09.2025 04:44:53
- Zuletzt bearbeitet 03.10.2025 15:39:40
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, allowing attackers to gain additional information about the server by checking if certain directories ...
CVE-2025-59950
- EPSS 0.03%
- Veröffentlicht 30.09.2025 04:43:45
- Zuletzt bearbeitet 03.10.2025 15:52:28
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management p...
CVE-2025-59948
- EPSS 0.03%
- Veröffentlicht 29.09.2025 23:15:32
- Zuletzt bearbeitet 03.10.2025 15:55:15
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not sanitize certain event handler attributes in feed content, so by finding a page that renders feed entries without CSP, it is possible to execute an XSS payload. The Al...
CVE-2025-57769
- EPSS 0.03%
- Veröffentlicht 29.09.2025 22:15:36
- Zuletzt bearbeitet 03.10.2025 15:58:53
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below contain a vulnerability where a specially crafted page can trick a user into executing arbitrary JS code or promoting a user in FreshRSS by obscuring UI elements in iframes. ...
CVE-2025-54875
- EPSS 0.09%
- Veröffentlicht 29.09.2025 22:15:36
- Zuletzt bearbeitet 03.10.2025 15:59:35
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker can create a new admin user when registration is enabled through the use of a hidden field used only in the user management admin ...
CVE-2025-54592
- EPSS 0.07%
- Veröffentlicht 29.09.2025 22:15:36
- Zuletzt bearbeitet 03.10.2025 16:04:21
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused by an attack...