Executive brief
Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler
Affected products
- Go miniflux.app/v2
Junglewise Threat Intelligence
CVE-2023-27592 · Severity: low · CVSS 3.1 · Published 2025-04-02
Technologies: miniflux.app/v2 (Go). Vendors: Go.
Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler