tt-rss records
6 published records for vendor tt-rss.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-863 Incorrect Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2020-25787Proof of concept | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16.tt-rss · tiny tiny rss · CWE-20 | Critical9.8 | — | 18.4% | Sep 19, 2020 |
39Monitor | CVE-2017-16896No exploit | A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.tt-rss · tiny tiny rss · CWE-89 | Critical9.8 | — | 1.5% | Nov 20, 2017 |
32Monitor | CVE-2020-25788No exploit | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16.tt-rss · tiny tiny rss · CWE-829 | High8.1 | — | 1.2% | Sep 19, 2020 |
30Monitor | CVE-2021-28373No exploit | The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid passwtt-rss · tiny tiny rss · CWE-863 | High7.5 | — | 0.9% | Mar 13, 2021 |
24Monitor | CVE-2017-1000035No exploit | Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attacktt-rss · tiny tiny rss · CWE-79 | Medium6.1 | — | 0.9% | Jul 17, 2017 |
24Monitor | CVE-2020-25789No exploit | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16.tt-rss · tiny tiny rss · CWE-79 | Medium6.1 | — | 0.9% | Sep 19, 2020 |
- CVE-2020-2578745Plan
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16.
CriticalCVSS 9.8Proof of conceptEPSS 18%tt-rss · tiny tiny rssSep 19, 2020
- CVE-2017-1689639Monitor
A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.
CriticalCVSS 9.8No exploitEPSS 1%tt-rss · tiny tiny rssNov 20, 2017
- CVE-2020-2578832Monitor
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16.
HighCVSS 8.1No exploitEPSS 1%tt-rss · tiny tiny rssSep 19, 2020
- CVE-2021-2837330Monitor
The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid passw
HighCVSS 7.5No exploitEPSS 1%tt-rss · tiny tiny rssMar 13, 2021
- CVE-2017-100003524Monitor
Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack
MediumCVSS 6.1No exploitEPSS 1%tt-rss · tiny tiny rssJul 17, 2017
- CVE-2020-2578924Monitor
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16.
MediumCVSS 6.1No exploitEPSS 1%tt-rss · tiny tiny rssSep 19, 2020