Critical
Low
Medium
CVE-2025-59950
Overview
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management page after the admin double clicks on a button insi...
Critical
Low
Medium
No items found.