« Volver al listado

Tt-rss

Tt-rss Tiny Tiny RSS: vulnerabilidades y CVE

Tt-rss Tiny Tiny RSS tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-28373Alta (7.5)0.93%—13 mar 2021
The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this issue only affected the git master branch for a short time.…
CVE-2020-25789Media (6.1)0.88%—19 sept 2020
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVE-2020-25788Alta (8.1)1.2%—19 sept 2020
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an error message.
CVE-2020-25787Crítica (9.8)18%—19 sept 2020
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.
CVE-2017-16896Crítica (9.8)1.5%—20 nov 2017
A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.
CVE-2017-1000035Media (6.1)0.89%—17 jul 2017
Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack