TT-Rss / Tiny Tiny Rss
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-28373 | The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this iss… | HIGH | 7.5 | Mar 13, 2021 |
| CVE-2020-25787 | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them. | CRITICAL | 9.8 | Sep 19, 2020 |
| CVE-2020-25788 | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an error mes… | HIGH | 8.1 | Sep 19, 2020 |
| CVE-2020-25789 | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document. | MEDIUM | 6.1 | Sep 19, 2020 |
| CVE-2017-16896 | A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter. | CRITICAL | 9.8 | Nov 20, 2017 |
| CVE-2017-1000035 | Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack | MEDIUM | 6.1 | Jul 13, 2017 |
Showing 1 to 6 of 6 CVEs