All 22 CVE vulnerabilities found in FreshRSS, with AI-generated Chinese analysis, references, and POCs.
This page aggregates known vulnerabilities for the FreshRSS open-source self-hosted news aggregator. The collection covers security issues ranging from cross-site scripting and SQL injection to remote code execution and privilege escalation flaws that have been publicly disclosed or assigned identifiers over the past several years. By reviewing this comprehensive list, users can track vendor advisories and patch releases to maintain a secure deployment, understand the characteristics and potential impact of specific weakness classes within the application's architecture, and look up a product's historical vulnerability trends to assess its overall security posture and development responsiveness. The data includes details on affected versions, severity ratings, and available mitigation strategies or workarounds. This resource is intended for system administrators, security researchers, and privacy-conscious users who rely on FreshRSS for aggregating content from various web feeds. It serves as a central reference point for understanding the specific risks associated with this software, helping stakeholders make informed decisions about updates, configuration hardening, and threat modeling. Regularly consulting this page allows teams to stay ahead of emerging threats and ensure that their instance remains protected against previously identified exploits.
Vendor: FreshRSS
All 22 known CVE vulnerabilities affecting FreshRSS with full Chinese analysis, references, and POCs where available.