Freshrss is a self-hosted feed aggregator and reader platform with a concentrated but prominent vulnerability footprint centered entirely on its single flagship product. The vendor's disclosure history reflects common weaknesses in server-side web applications: cross-site scripting, improper access control, cross-site request forgery, path traversal, and UI-framing issues that arise from input handling and session management in PHP-based web services. Vulnerabilities affecting Freshrss skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the direct risk that flaws in a self-hosted service present to user data and system integrity. Defenders should treat Freshrss updates as priority where the application is deployed internally or exposed on semi-trusted networks, and inventory instances for patching cadence; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freshrss over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68932CRITICAL FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() and uniqid()) to generate rememb | Dec 27, 2025 | 9.8 | 34 | NO | NO |
CVE-2018-19782MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) | Jan 30, 2019 | 6.1 | 32 | NO | YES |
CVE-2025-54875CRITICAL FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker can create a new admin user when registration is enabled thr | Sep 29, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-54592CRITICAL FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains a | Sep 29, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-58173HIGH FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it's possible to call ` | Dec 16, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-62166HIGH FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the defa | Mar 9, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-68148HIGH FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a | Dec 27, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-54591HIGH FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of default admin users, due to lack of access checking in the Fr | Sep 29, 2025 | 7.5 | 25 | NO | NO |
CVE-2022-23497HIGH FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition to user preferences, such configurations contain hashed pas | Dec 9, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-54593HIGH FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the FreshRSS server by modifying t | Aug 1, 2025 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freshrss.
Media articles that mention a CVE ID that affects a product developed by Freshrss — matched by CVE ID, not by vendor name.