FreshRSS
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 29, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →FreshRSS has an IDOR which allows for viewing feeds of any user and leaking tokens
FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After
FreshRSS has weak cryptographic randomness in remember-me token and nonce generation
FreshRSS has Logout CSRF that Leads to DoS via <track src>
FreshRSS vulnerable to authenticated RCE via path traversal inside include()
FreshRSS: Double clickjacking can lead to privilege escalation
FreshRSS is vulnerable to directory enumeration by setting path in its theme field
FreshRSS is vulnerable to XSS due to lack of CSP on HTML query page
FressRSS: Clickjacking can lead to XSS and/or privilege escalation
FreshRSS: Unauthorized creation of admin user when registration is enabled
Monitor FreshRSS in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.