2025-06-04 19:59:39
GitHub_M
PUBLISHED
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, HTML is sanitized improperly inside the `` attribute, which leads to cross-site scripting (XSS) by loading an attackers UserJS inside `