Misskey

Misskey

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.63%
  • Veröffentlicht 22.02.2023 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:48:26

Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3....

  • EPSS 0.54%
  • Veröffentlicht 22.02.2023 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:48:26

Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is subject to a cross site scripting vulnerability due to insufficient URL validation. Arbitrary JavaScript is executed when a malici...

  • EPSS 0.51%
  • Veröffentlicht 22.02.2023 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:48:26

Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL during `miauth` authentication in Misskey, arbitrary JavaScript can be executed when a user allows the link. All versions below 13.3.1 ...

  • EPSS 0.54%
  • Veröffentlicht 22.02.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:49:12

Misskey is an open source, decentralized social media platform. In versions prior to 13.5.0 the link to the instance to the sender that appears when viewing a user or note received through ActivityPub is not properly validated, so by inserting a URL ...

  • EPSS 0.24%
  • Veröffentlicht 07.09.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:18:51

Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public informatio...

  • EPSS 0.32%
  • Veröffentlicht 27.08.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:46

Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the web client built-in dialog to display a malicious string, leading to cross-site scripting (XSS). XSS could compromise the API req...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 29.07.2019 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:11

Misskey before 10.102.4 allows hijacking a user's token.