Inverle
5 exploits
Active since Jun 2025
FreshRSS < 1.28.0 - Authorization Bypass via Master Authentication Token
CVSS 7.5
FreshRSS < 1.26.2 - Information Disclosure via Directory Existence Check
CVSS 7.5
FreshRSS < 1.27.0 - Authenticated Cross-Site Scripting via Feed Event Handler Attributes
CVSS 6.7
FreshRSS < 1.27.0 - Path Traversal via Theme Field
CVSS 5.3
FreshRSS 1.27.0-1.28.0 - Denial of Service via Proxy Retry-After Header Manipulation
CVSS 4.3