Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freshrss

First CVE: Jan 30, 2019Active for: 7 yearsTotal CVEs: 22
40.7
VTI Score
High

Freshrss is a self-hosted feed aggregator and reader platform with a concentrated but prominent vulnerability footprint centered entirely on its single flagship product. The vendor's disclosure history reflects common weaknesses in server-side web applications: cross-site scripting, improper access control, cross-site request forgery, path traversal, and UI-framing issues that arise from input handling and session management in PHP-based web services. Vulnerabilities affecting Freshrss skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the direct risk that flaws in a self-hosted service present to user data and system integrity. Defenders should treat Freshrss updates as priority where the application is deployed internally or exposed on semi-trusted networks, and inventory instances for patching cadence; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
4.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Freshrss over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2019
7 years ago
Most Recent CVE
Mar 9, 2026
137 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-68932CRITICAL
FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() and uniqid()) to generate rememb
Dec 27, 20259.834NONO
CVE-2018-19782MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2)
Jan 30, 20196.132NOYES
CVE-2025-54875CRITICAL
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker can create a new admin user when registration is enabled thr
Sep 29, 20259.831NONO
CVE-2025-54592CRITICAL
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains a
Sep 29, 20259.830NONO
CVE-2025-58173HIGH
FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it's possible to call `
Dec 16, 20258.828NONO
CVE-2025-62166HIGH
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the defa
Mar 9, 20267.525NONO
CVE-2025-68148HIGH
FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a
Dec 27, 20257.525NONO
CVE-2025-54591HIGH
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of default admin users, due to lack of access checking in the Fr
Sep 29, 20257.525NONO
CVE-2022-23497HIGH
FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition to user preferences, such configurations contain hashed pas
Dec 9, 20227.525NONO
CVE-2025-54593HIGH
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the FreshRSS server by modifying t
Aug 1, 20257.223NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
50%
36%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network21 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (90.9%)
High2 (9.1%)
Unknown0 (0.0%)
User Interaction
None14 (63.6%)
Unknown0 (0.0%)
Required8 (36.4%)
Privileges Required
Low8 (36.4%)
High1 (4.5%)
None13 (59.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freshrss.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freshrss — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freshrss's Products

View all 2 CNAs →

Top CWEs