CVE-2017-16896: Tt-Rss Tiny Tiny Rss

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.

Affected products

  • Tt-Rss Tiny Tiny Rss: version 17.4 only

Published 2017-11-20. Last modified 2026-06-17.