CVE-2026-28433
- EPSS 0.01%
- Veröffentlicht 09.03.2026 21:21:06
- Zuletzt bearbeitet 13.03.2026 17:17:07
Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but prior to 2026.3.1, contain a vulnerability that allows importing other users' data due to lack of ownership validation. The impact...
CVE-2026-28432
- EPSS 0.02%
- Veröffentlicht 09.03.2026 21:19:43
- Zuletzt bearbeitet 13.03.2026 17:18:06
Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all server...
CVE-2026-28431
- EPSS 0.05%
- Veröffentlicht 09.03.2026 21:17:32
- Zuletzt bearbeitet 13.03.2026 17:18:44
Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that allows bad actors access to data that they ordinarily wouldn't be able to access du...
CVE-2025-66482
- EPSS 0.08%
- Veröffentlicht 15.12.2025 23:18:37
- Zuletzt bearbeitet 06.01.2026 19:41:47
Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.9.1, an opt...
CVE-2025-66402
- EPSS 0.04%
- Veröffentlicht 15.12.2025 23:09:57
- Zuletzt bearbeitet 06.01.2026 19:42:01
Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 20...
CVE-2025-46559
- EPSS 0.15%
- Veröffentlicht 05.05.2025 18:38:36
- Zuletzt bearbeitet 03.09.2025 18:29:40
Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access ...
CVE-2025-46340
- EPSS 0.21%
- Veröffentlicht 05.05.2025 18:35:37
- Zuletzt bearbeitet 03.09.2025 18:47:53
Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject ...
CVE-2025-25306
- EPSS 0.05%
- Veröffentlicht 10.03.2025 18:13:45
- Zuletzt bearbeitet 26.11.2025 16:24:21
Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority i...
CVE-2025-24897
- EPSS 0.04%
- Veröffentlicht 11.02.2025 16:15:51
- Zuletzt bearbeitet 26.11.2025 16:32:39
Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashbo...
CVE-2025-24896
- EPSS 0.33%
- Veröffentlicht 11.02.2025 16:15:51
- Zuletzt bearbeitet 20.02.2025 15:48:37
Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie for authentication purposes in Bull Dashboard, but this remains undelete...