Miniflux Project maintains a lightweight, open-source feed-reader and content-aggregation application that exposes a web-facing interface for managing subscriptions and displaying syndicated content. Its observed vulnerability landscape reflects this role, with recurrent patterns in information disclosure, cross-site scripting, access control, and server-side request forgery—weakness classes typical of web applications handling user input, session state, and external content fetching. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Miniflux Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21885MEDIUM Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side | Jan 8, 2026 | 6.5 | 23 | NO | NO |
CVE-2023-27591HIGH Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR | Mar 17, 2023 | 7.5 | 23 | NO | NO |
CVE-2025-67713MEDIUM Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishing flows after login. Protocol-r | Dec 11, 2025 | 6.1 | 21 | NO | NO |
CVE-2023-27592MEDIUM Miniflux is a feed reader. Since v2.0.25, Miniflux will automatically proxy images served over HTTP to prevent mixed content errors.
When an outbound request made by the Go HTTP | Mar 17, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Miniflux Project.
Media articles that mention a CVE ID that affects a product developed by Miniflux Project — matched by CVE ID, not by vendor name.