Junglewise Threat Intelligence

CVE-2023-27592: Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler

CVE-2023-27592 · Severity: low · CVSS 3.1 · Published 2025-04-02

Technologies: miniflux.app/v2 (Go). Vendors: Go.

Executive brief

Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler

Affected products

  • Go miniflux.app/v2

Related threats