NA - CVE-2025-31134 - FreshRSS is a self-hosted RSS feed aggregator....
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if certain directories exist. An attacker can, for...
NA - CVE-2025-31136 - FreshRSS is a self-hosted RSS feed aggregator....
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the feeds page. This occurs by combining a cross-site scripting (XSS) issue...
NA - CVE-2025-31482 - FreshRSS is a self-hosted RSS feed aggregator....
FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedly logged out after fetching a malicious feed entry, effectively causing that...
NA - CVE-2025-32015 - FreshRSS is a self-hosted RSS feed aggregator....
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, HTML is sanitized improperly inside the `` attribute, which leads to cross-site scripting (XSS) by loading an attacker's...
NA - CVE-2025-46339 - FreshRSS is a self-hosted RSS feed aggregator....
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding a given URL as a feed with the proxy set to an attacker-controlled one...
NA - CVE-2025-48888 - Deno is a JavaScript, TypeScript, and...
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2.13, and 2.3.2, `deno run --allow-read --deny-read main.ts` results in...