Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-29065 Source A critical security vulnerability in changedetection.io allows attackers to overwrite arbitrary files on the server by uploading malicious ZIP archives through the backup restore functionality. |
changedetection.io | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-33981 Source A vulnerability in changedetection.io allows users to read all server environment variables through jq filters, including password hashes and other secrets. |
changedetection.io | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-35490 Source A web monitoring service has a critical authentication flaw where 13 routes are accidentally accessible without login, allowing attackers to download and delete backups containing sensitive data. |
changedetection.io | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-41895 Source An XML processing vulnerability in changedetection.io allows attackers to read local files from the server when they control the content of a monitored XML/RSS URL and XPath filters are used. |
changedetection.io | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-43891 Source A security vulnerability in changedetection.io allows attackers to read local files on the server by restoring malicious backup files that contain harmful paths in the history file. |
changedetection.io | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-23211 Source A vulnerability in Tandoor Recipes software allows any user to execute arbitrary commands on the server by exploiting unsafe template processing in recipe instructions. |
Tandoor Recipes | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2025-23212 Source A vulnerability in Tandoor Recipes' external storage feature allows any user to browse and read the contents of arbitrary files on the server, including sensitive system files. |
Tandoor Recipes | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-23213 Source The file upload feature in Tandoor Recipes allows uploading arbitrary files like HTML and SVG that can contain malicious JavaScript code. This enables cross-site scripting attacks when these files are accessed directly. |
Tandoor Recipes | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-25991 Source A vulnerability in Tandoor Recipes software allows authenticated users to force the server to make requests to arbitrary internal or external addresses by exploiting HTTP redirects in the recipe import feature. |
Tandoor Recipes | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-25964 Source A path traversal vulnerability in Tandoor Recipes allows authenticated users with import permissions to read arbitrary files on the server, including system files and configuration files, potentially leading to complete system compromise. |
Tandoor Recipes | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-27460 Source A vulnerability in Tandoor Recipes software allows authenticated users to crash the server or severely slow it down by uploading specially crafted ZIP files that consume excessive memory. |
Tandoor Recipes | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-28503 Source A security vulnerability in Tandoor Recipes software allows administrators to view and trigger synchronization operations and logs from other spaces, even though they should only have access to their own space. |
Tandoor Recipes | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-29055 Source A vulnerability in the Tandoor Recipes cookbook software fails to remove sensitive EXIF data like GPS coordinates, camera model, and timestamps from WebP images (the default format for modern smartphones), exposing this private information to all users. |
Tandoor Recipes | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-33153 Source A security vulnerability in Tandoor Recipes software allows any authenticated user to view complete SQL database queries through a hidden debug parameter, exposing the entire database structure and access control logic. |
Tandoor Recipes | Self-hosted apps | Low | 07.06.2026 |
| CVE-2026-33148 Source A security vulnerability in Tandoor Recipes software allows attackers to inject additional parameters into API requests by using special characters in search queries. This can cause server crashes and result in denial of service. |
Tandoor Recipes | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-33152 Source A vulnerability in Tandoor Recipes software allows unlimited password attacks through the API because rate limiting only applies to the regular login page, not to API endpoints using Basic Authentication. |
Tandoor Recipes | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-33149 Source The Tandoor Recipes software accepts arbitrary Host headers by default without validation, allowing attackers to manipulate URLs in emails and API responses. Most critical: invitation links in emails can be redirected to attacker servers, enabling theft of invitation tokens. |
Tandoor Recipes | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-35045 Source A security vulnerability in Tandoor Recipes v2.6.1 allows authenticated users to modify private recipes belonging to other users in the same workspace and manipulate their visibility, bypassing access controls. |
Tandoor Recipes | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-35046 Source A vulnerability in Tandoor Recipes v2.6.1 allows authenticated users to inject malicious CSS code into recipe instructions, which is served uncensored through the API and can lead to visual manipulation or data theft when rendered as HTML. |
Tandoor Recipes | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-35488 Source A vulnerability in Tandoor Recipes software allows users with shared access to recipe books to delete or overwrite them, even though shared access is intended to be read-only. |
Tandoor Recipes | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-35489 Source A vulnerability in Tandoor Recipes software allows attackers to crash the server and access other users' data by sending invalid inputs to an API endpoint. |
Tandoor Recipes | Self-hosted apps | High | 07.06.2026 |
| GHSA-89pw-5qxc-7v86 Source A security vulnerability in Tandoor Recipes software allows authenticated users with recipe editing permissions to inject malicious JavaScript code into recipe instructions that then executes in other users' browsers. |
Tandoor Recipes | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2022-23497 Source FreshRSS RSS reader has a vulnerability allowing attackers to remotely access user configuration files containing hashed passwords and user databases when SQLite is used, if they can guess usernames. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2023-22481 Source FreshRSS stores passwords in plain text in log files when Google Reader API authentication fails, allowing attackers with log access to view sensitive login credentials. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-31136 Source A security vulnerability in FreshRSS allows attackers to execute malicious JavaScript code through manipulated RSS feed favicons, enabling them to gain access to user accounts or even execute code on the server if targeting administrators. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-31482 Source FreshRSS RSS reader has a vulnerability where malicious feed content can automatically and repeatedly log out users, making their account practically unusable. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-31134 Source FreshRSS contains a vulnerability that allows attackers to check if certain directories exist on the server through manipulated URLs, enabling them to gather information about the server structure. |
FreshRSS | Self-hosted apps | Low | 07.06.2026 |
| CVE-2025-32015 Source FreshRSS, an RSS reader software, inadequately filters HTML content in feeds, allowing attackers to inject malicious JavaScript code through manipulated RSS feeds. This enables theft of user data or takeover of administrator accounts. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-46341 Source A vulnerability in FreshRSS allows attackers to impersonate other users when HTTP authentication via reverse proxy is used, by sending specially crafted requests with spoofed user headers and potentially gaining administrative privileges. |
FreshRSS | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-46339 Source A vulnerability in FreshRSS allows users to manipulate RSS feed favicon images for all other users by changing the website URL in the feed settings. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-57769 Source A security vulnerability in FreshRSS allows attackers to trick users into executing malicious JavaScript code or escalating their user privileges by hiding UI elements within iframes. |
FreshRSS | Self-hosted apps | Low | 07.06.2026 |
| CVE-2025-54593 Source A security vulnerability in FreshRSS before version 1.26.2 allows administrators to execute arbitrary code on the server by changing the update URL to one they control. |
FreshRSS | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-59950 Source FreshRSS has a security vulnerability where attackers can trick administrators into unintentionally promoting user privileges through a special clickjacking technique that bypasses protection measures using a URL parameter. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-54592 Source FreshRSS, an RSS reader software, fails to properly terminate user sessions during logout. Session cookies remain active and can be reused by attackers, leading to potential session hijacking vulnerabilities. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-54591 Source FreshRSS RSS reader has missing access checks in certain endpoints, allowing unauthorized users to view information about RSS feeds and tags of the default admin user, including feed names and unread article counts. |
FreshRSS | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-54875 Source A critical security vulnerability in FreshRSS allows attackers to register as administrators when user registration is enabled by manipulating a hidden form field, thereby gaining complete access to the application and all user data. |
FreshRSS | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2025-59948 Source FreshRSS fails to properly filter certain event handler attributes in feed content, allowing attackers to inject malicious JavaScript code through crafted RSS feeds. This enables account takeover and administrative actions if the victim is an administrator. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-61586 Source FreshRSS contains a vulnerability that allows attackers to gather information about the server by checking if certain directories exist, revealing details like installed software or PHP versions. |
FreshRSS | Self-hosted apps | Low | 07.06.2026 |
| CVE-2025-58173 Source A critical security vulnerability in FreshRSS allows regular users to perform administrative actions through path traversal in the language parameter, including admin login, user creation, or code execution. |
FreshRSS | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2025-59949 Source FreshRSS RSS reader contains a vulnerability that allows attackers to forcibly log out users by creating malicious RSS feeds with special HTML elements that perform cross-site request forgery attacks. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-68148 Source FreshRSS, an RSS reader software, can be blocked by manipulated server responses that specify long wait times, preventing all users from adding popular feeds to the application. |
FreshRSS | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-68932 Source FreshRSS uses weak random number generators for authentication tokens, allowing attackers to predict valid session tokens and permanently take over user accounts. |
FreshRSS | Self-hosted apps | Low | 07.06.2026 |
| CVE-2025-62166 Source An authentication logic flaw in FreshRSS allows anonymous visitors to view private RSS feeds and settings of any user, even though normally only default feeds should be publicly accessible. |
FreshRSS | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-68402 Source A critical vulnerability in FreshRSS allowed attackers to log in with any password because the password verification always succeeded due to a programming error. |
FreshRSS | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2025-53826 Source File Browser, a file management application, fails to properly invalidate authentication tokens when users log out, allowing stolen tokens to continue providing unauthorized access until they naturally expire. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-54092 Source File Browser doesn't check maximum password length during login, allowing attackers to send extremely long passwords that consume excessive CPU and memory during hashing, potentially crashing the service. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-64523 Source A security vulnerability in the File Browser application allows authenticated users to delete other users' shared links without authorization due to missing ownership validation checks. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-22871 Source A critical vulnerability in the Go standard library used by File Browser allows HTTP request smuggling attacks through improper handling of line terminators in HTTP chunk data. |
File Browser | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-23849 Source A security vulnerability in File Browser software allows attackers to discover valid usernames by measuring login response times, as authentication takes longer for existing users than for non-existing ones. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-25890 Source A vulnerability in File Browser allows authenticated users to bypass access restrictions by using multiple slashes in URLs, enabling them to access forbidden files. |
File Browser | Self-hosted apps | High | 07.06.2026 |