Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FreshRSS — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting FreshRSS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreshRSS is an open-source, self-hosted RSS aggregator designed to allow users to monitor multiple news feeds from a single interface. As a PHP-based web application, it has historically been associated with twenty-two recorded Common Vulnerabilities and Exposures (CVEs). The most prevalent vulnerability classes include SQL injection, cross-site scripting (XSS), and remote code execution (RCE), often stemming from insufficient input validation and improper handling of user-supplied data. While the project maintains an active development cycle to address these issues, the frequency of past exploits highlights the risks inherent in complex web interfaces. Notable incidents have primarily involved authenticated attacks or specific configuration weaknesses rather than widespread, unauthenticated breaches. Users are advised to keep installations updated and restrict access to trusted networks to mitigate potential exposure to these known security flaws.

Top products by FreshRSS: FreshRSS
CVE ID Title CVSS Severity Published
CVE-2025-68402 FreshRSS has an authentication bypass due to truncated bcrypt hash [edge branch] — FreshRSS CWE-287 5.3AI Medium AI 2026-03-09
CVE-2025-62166 FreshRSS has an IDOR which allows for viewing feeds of any user and leaking tokens — FreshRSS CWE-284 7.5 High 2026-03-09
CVE-2025-68148 FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After — FreshRSS CWE-770 4.3 Medium 2025-12-26
CVE-2025-68932 FreshRSS has weak cryptographic randomness in remember-me token and nonce generation — FreshRSS CWE-338 9.8 - 2025-12-26
CVE-2025-59949 FreshRSS has Logout CSRF that Leads to DoS via <track src> — FreshRSS CWE-352 5.3 Medium 2025-12-18
CVE-2025-58173 FreshRSS vulnerable to authenticated RCE via path traversal inside include() — FreshRSS CWE-20 8.8AI High AI 2025-12-15
CVE-2025-59950 FreshRSS: Double clickjacking can lead to privilege escalation — FreshRSS CWE-1021 6.7 Medium 2025-09-29
CVE-2025-61586 FreshRSS is vulnerable to directory enumeration by setting path in its theme field — FreshRSS CWE-22 5.3 - 2025-09-29
CVE-2025-59948 FreshRSS is vulnerable to XSS due to lack of CSP on HTML query page — FreshRSS CWE-79 6.7 Medium 2025-09-29
CVE-2025-57769 FressRSS: Clickjacking can lead to XSS and/or privilege escalation — FreshRSS CWE-79 8.8AI High AI 2025-09-29
CVE-2025-54875 FreshRSS: Unauthorized creation of admin user when registration is enabled — FreshRSS CWE-284 9.8 Critical 2025-09-29
CVE-2025-54592 FreshRSS has Incomplete Session Termination on Logout — FreshRSS CWE-613 7.1AI High AI 2025-09-29
CVE-2025-54591 FreshRSS: Unauthenticated users can view default user's information — FreshRSS CWE-284 7.5 High 2025-09-29
CVE-2025-54593 FreshRSS is vulnerable to RCE attacks by authenticated admin — FreshRSS CWE-94 7.2 High 2025-08-01
CVE-2025-46341 Privilege escalation via SSRF when using HTTP auth — FreshRSS CWE-918 7.1 High 2025-06-04
CVE-2025-46339 FreshRSS vulnerable to favicon cache poisoning via proxy — FreshRSS CWE-349 4.3 Medium 2025-06-04
CVE-2025-32015 FreshRSS vulnerable to Cross-site Scripting by embedding <script> tag inside <iframe srcdoc> — FreshRSS CWE-79 6.7 Medium 2025-06-04
CVE-2025-31482 FreshRSS vulnerable to DoS by malicious feed entry loading logout URL — FreshRSS CWE-352 4.3 Medium 2025-06-04
CVE-2025-31136 FreshRSS vulnerable to Cross-site Scripting by <iframe>'ing a vulnerable same-origin page in a feed entry — FreshRSS CWE-79 6.7 Medium 2025-06-04
CVE-2025-31134 FreshRSS vulnerable to directory enumeration via ext.php — FreshRSS CWE-201 5.3AI Medium AI 2025-06-04
CVE-2023-22481 Sensitive information exposure in the logs of greader API in FreshRSS — FreshRSS CWE-532 4.0 Medium 2023-03-06
CVE-2022-23497 Insecure file access in FreshRSS — FreshRSS CWE-200 6.5 Medium 2022-12-09

This page lists every published CVE security advisory associated with FreshRSS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.