Tt Rss maintains Tiny Tiny RSS, a self-hosted RSS feed reader and aggregation application that processes untrusted feed content from diverse sources. The vulnerabilities associated with this vendor reflect the input-handling and web-application context inherent to a feed-processing tool that consumes and renders arbitrary external feeds. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tt Rss over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25787CRITICAL An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them. | Sep 19, 2020 | 9.8 | 52 | NO | YES |
CVE-2017-16896CRITICAL A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter. | Nov 20, 2017 | 9.8 | 31 | NO | NO |
CVE-2020-25788HIGH An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an error message. | Sep 19, 2020 | 8.1 | 26 | NO | NO |
CVE-2021-28373HIGH The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this issue only affected the | Mar 13, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-25789MEDIUM An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document. | Sep 19, 2020 | 6.1 | 21 | NO | NO |
CVE-2017-1000035MEDIUM Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack | Jul 17, 2017 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tt Rss.
Media articles that mention a CVE ID that affects a product developed by Tt Rss — matched by CVE ID, not by vendor name.