Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FreshRSS — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in FreshRSS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the FreshRSS open-source self-hosted news aggregator. The collection covers security issues ranging from cross-site scripting and SQL injection to remote code execution and privilege escalation flaws that have been publicly disclosed or assigned identifiers over the past several years. By reviewing this comprehensive list, users can track vendor advisories and patch releases to maintain a secure deployment, understand the characteristics and potential impact of specific weakness classes within the application's architecture, and look up a product's historical vulnerability trends to assess its overall security posture and development responsiveness. The data includes details on affected versions, severity ratings, and available mitigation strategies or workarounds. This resource is intended for system administrators, security researchers, and privacy-conscious users who rely on FreshRSS for aggregating content from various web feeds. It serves as a central reference point for understanding the specific risks associated with this software, helping stakeholders make informed decisions about updates, configuration hardening, and threat modeling. Regularly consulting this page allows teams to stay ahead of emerging threats and ensure that their instance remains protected against previously identified exploits.

Vendor: FreshRSS

CVE IDTitleCVSSSeverityPublished
CVE-2025-68402 FreshRSS has an authentication bypass due to truncated bcrypt hash [edge branch] CWE-287 5.3AIMediumAI2026-03-09
CVE-2025-62166 FreshRSS has an IDOR which allows for viewing feeds of any user and leaking tokens CWE-284 7.5 High2026-03-09
CVE-2025-68148 FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After CWE-770 4.3 Medium2025-12-26
CVE-2025-68932 FreshRSS has weak cryptographic randomness in remember-me token and nonce generation CWE-338 9.8 -2025-12-26
CVE-2025-59949 FreshRSS has Logout CSRF that Leads to DoS via <track src> CWE-352 5.3 Medium2025-12-18
CVE-2025-58173 FreshRSS vulnerable to authenticated RCE via path traversal inside include() CWE-20 8.8AIHighAI2025-12-15
CVE-2025-59950 FreshRSS: Double clickjacking can lead to privilege escalation CWE-1021 6.7 Medium2025-09-29
CVE-2025-61586 FreshRSS is vulnerable to directory enumeration by setting path in its theme field CWE-22 5.3 -2025-09-29
CVE-2025-59948 FreshRSS is vulnerable to XSS due to lack of CSP on HTML query page CWE-79 6.7 Medium2025-09-29
CVE-2025-57769 FressRSS: Clickjacking can lead to XSS and/or privilege escalation CWE-79 8.8AIHighAI2025-09-29
CVE-2025-54875 FreshRSS: Unauthorized creation of admin user when registration is enabled CWE-284 9.8 Critical2025-09-29
CVE-2025-54592 FreshRSS has Incomplete Session Termination on Logout CWE-613 7.1AIHighAI2025-09-29
CVE-2025-54591 FreshRSS: Unauthenticated users can view default user's information CWE-284 7.5 High2025-09-29
CVE-2025-54593 FreshRSS is vulnerable to RCE attacks by authenticated admin CWE-94 7.2 High2025-08-01
CVE-2025-46341 Privilege escalation via SSRF when using HTTP auth CWE-918 7.1 High2025-06-04
CVE-2025-46339 FreshRSS vulnerable to favicon cache poisoning via proxy CWE-349 4.3 Medium2025-06-04
CVE-2025-32015 FreshRSS vulnerable to Cross-site Scripting by embedding <script> tag inside <iframe srcdoc> CWE-79 6.7 Medium2025-06-04
CVE-2025-31482 FreshRSS vulnerable to DoS by malicious feed entry loading logout URL CWE-352 4.3 Medium2025-06-04
CVE-2025-31136 FreshRSS vulnerable to Cross-site Scripting by <iframe>'ing a vulnerable same-origin page in a feed entry CWE-79 6.7 Medium2025-06-04
CVE-2025-31134 FreshRSS vulnerable to directory enumeration via ext.php CWE-201 5.3AIMediumAI2025-06-04
CVE-2023-22481 Sensitive information exposure in the logs of greader API in FreshRSS CWE-532 4.0 Medium2023-03-06
CVE-2022-23497 Insecure file access in FreshRSS CWE-200 6.5 Medium2022-12-09

All 22 known CVE vulnerabilities affecting FreshRSS with full Chinese analysis, references, and POCs where available.