Skip to main content

Vendor archive

tt-rss CVEs

Beta · best-effort

6 CVEs tagged to vendor tt-rss2 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2021-28373

Published Mar 13, 2021

The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this issue only affected the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25789

Published Sep 19, 2020

An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25788

Published Sep 19, 2020

An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an error message.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25787

Published Sep 19, 2020

An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16896

Published Nov 20, 2017

A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1