CVE-2025-31136 - FreshRSS Cross-Site Scripting (XSS) Vulnerability
CVE ID : CVE-2025-31136
Published : June 4, 2025, 8:15 p.m. | 1 hour, 56 minutes ago
Description : FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the feeds page. This occurs by combining a cross-site scripting (XSS) issue that occurs in `f.php` when SVG favicons are downloaded from an attacker-controlled feed containing `
Published : June 4, 2025, 8:15 p.m. | 1 hour, 56 minutes ago
Description : FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the feeds page. This occurs by combining a cross-site scripting (XSS) issue that occurs in `f.php` when SVG favicons are downloaded from an attacker-controlled feed containing `