CRITICAL9.8CVE-2020-25787An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. from 0, < 21~git20210204.b4cbc79+dfsg-1
CRITICAL9.8CVE-2017-16896A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter. from 0, < 17.4+git20180312+dfsg-1
HIGH8.1CVE-2020-25788An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. from 0, < 21~git20210204.b4cbc79+dfsg-1
MEDIUM6.1An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16.
from 0, < 21~git20210204.b4cbc79+dfsg-1
MEDIUM6.1Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack
from 0, < 17.1+git20170410+dfsg-1