Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FreshRSS — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in FreshRSS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses for the open-source RSS aggregator FreshRSS, categorized by Common Weakness Enumeration types and specific product tags. It collects vulnerability records spanning from the product’s initial public release through the most recent patch cycles, ensuring a comprehensive historical view of its security posture. By consolidating data from vendor advisories, third-party trackers, and community reports, this resource allows users to track FreshRSS’s official security responses and understand the evolution of specific weakness classes such as cross-site scripting or authentication bypasses within the application. Readers can use this aggregated view to look up the complete vulnerability history of FreshRSS, helping developers and system administrators assess risk exposure, verify patch application, and contextualize individual CVEs against the broader landscape of reported issues. The data is structured to facilitate deep analysis of recurring security patterns, enabling stakeholders to make informed decisions about upgrade schedules and configuration hardening. This centralized view removes the need to query multiple disparate sources, providing a clear, chronological record of how FreshRSS has addressed security flaws over time. It serves as a reference point for security audits and helps clarify the relationship between reported vulnerabilities and the underlying codebase changes. Ultimately, this page aims to enhance transparency and support proactive security management for all FreshRSS deployments.

Vendor: FreshRSS

CVE ID Title CVSS Severity Published
CVE-2025-68402 FreshRSS has an authentication bypass due to truncated bcrypt hash [edge branch] CWE-287 5.3AI Medium AI 2026-03-09
CVE-2025-62166 FreshRSS has an IDOR which allows for viewing feeds of any user and leaking tokens CWE-284 7.5 High 2026-03-09
CVE-2025-68148 FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After CWE-770 4.3 Medium 2025-12-26
CVE-2025-68932 FreshRSS has weak cryptographic randomness in remember-me token and nonce generation CWE-338 9.8 - 2025-12-26
CVE-2025-59949 FreshRSS has Logout CSRF that Leads to DoS via <track src> CWE-352 5.3 Medium 2025-12-18
CVE-2025-58173 FreshRSS vulnerable to authenticated RCE via path traversal inside include() CWE-20 8.8AI High AI 2025-12-15
CVE-2025-59950 FreshRSS: Double clickjacking can lead to privilege escalation CWE-1021 6.7 Medium 2025-09-29
CVE-2025-61586 FreshRSS is vulnerable to directory enumeration by setting path in its theme field CWE-22 5.3 - 2025-09-29
CVE-2025-59948 FreshRSS is vulnerable to XSS due to lack of CSP on HTML query page CWE-79 6.7 Medium 2025-09-29
CVE-2025-57769 FressRSS: Clickjacking can lead to XSS and/or privilege escalation CWE-79 8.8AI High AI 2025-09-29
CVE-2025-54875 FreshRSS: Unauthorized creation of admin user when registration is enabled CWE-284 9.8 Critical 2025-09-29
CVE-2025-54592 FreshRSS has Incomplete Session Termination on Logout CWE-613 7.1AI High AI 2025-09-29
CVE-2025-54591 FreshRSS: Unauthenticated users can view default user's information CWE-284 7.5 High 2025-09-29
CVE-2025-54593 FreshRSS is vulnerable to RCE attacks by authenticated admin CWE-94 7.2 High 2025-08-01
CVE-2025-46341 Privilege escalation via SSRF when using HTTP auth CWE-918 7.1 High 2025-06-04
CVE-2025-46339 FreshRSS vulnerable to favicon cache poisoning via proxy CWE-349 4.3 Medium 2025-06-04
CVE-2025-32015 FreshRSS vulnerable to Cross-site Scripting by embedding <script> tag inside <iframe srcdoc> CWE-79 6.7 Medium 2025-06-04
CVE-2025-31482 FreshRSS vulnerable to DoS by malicious feed entry loading logout URL CWE-352 4.3 Medium 2025-06-04
CVE-2025-31136 FreshRSS vulnerable to Cross-site Scripting by <iframe>'ing a vulnerable same-origin page in a feed entry CWE-79 6.7 Medium 2025-06-04
CVE-2025-31134 FreshRSS vulnerable to directory enumeration via ext.php CWE-201 5.3AI Medium AI 2025-06-04
CVE-2023-22481 Sensitive information exposure in the logs of greader API in FreshRSS CWE-532 4.0 Medium 2023-03-06
CVE-2022-23497 Insecure file access in FreshRSS CWE-200 6.5 Medium 2022-12-09

All 22 known CVE vulnerabilities affecting FreshRSS with full Chinese analysis, references, and POCs where available.