Skip to content
Noroxi

Misskey records

28 published records for vendor misskey.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
71.4%
Median publish → KEV
No record has entered KEV

All records

28 records
  • SQL injection of notes/search-by-tag

    CriticalCVSS 9.8No exploitEPSS 1%

    misskey · misskeyFeb 22, 2023

  • Misskey vulnerable to improper authorization when accessing with third-party application

    CriticalCVSS 9.6No exploitEPSS 1%

    misskey · misskeyDec 29, 2023

  • Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes

    CriticalCVSS 9.3No exploitEPSS 0%

    misskey · misskeyMar 10, 2025

  • Misskey lacks proper authorization checks and input validation

    CriticalCVSS 9.2No exploitEPSS 0%

    misskey · misskeyMar 10, 2026

  • Lack of media type verification of Activity Streams objects allows impersonation and takeover of remote accounts

    HighCVSS 8.8No exploitEPSS 1%

    misskey · misskeyFeb 19, 2024

  • Missing validation allows spoofed profiles in Misskey

    HighCVSS 8.8No exploitEPSS 0%

    misskey · misskeyDec 18, 2024

  • Missing validation allows spoofed profiles and notes in Misskey

    HighCVSS 8.8No exploitEPSS 0%

    misskey · misskeyDec 18, 2024

  • Misskey allows token to remain valid in cookie after signing out

    HighCVSS 8.1No exploitEPSS 1%

    misskey · misskeyFeb 11, 2025

  • Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributes

    HighCVSS 8.2No exploitEPSS 0%

    misskey · misskeyFeb 11, 2025

  • Misskey allows users to bypass authentication of Bull dashboard

    HighCVSS 7.5No exploitEPSS 1%

    misskey · misskeyOct 4, 2023

  • Misskey Directory Traversal Vulnerability in AiScript via `Mk:api`

    HighCVSS 7.5No exploitEPSS 0%

    misskey · misskeyMay 5, 2025

  • Misskey's missing signature validation allows arbitrary users to impersonate any remote user.

    HighCVSS 7.5No exploitEPSS 0%

    misskey · misskeyNov 29, 2023

  • Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activities

    HighCVSS 7.5No exploitEPSS 0%

    misskey · misskeyJun 3, 2024

  • misskey.js's export data contains private post data

    HighCVSS 7.1No exploitEPSS 0%

    misskey · misskeyDec 15, 2025

  • HTTP signature verification can be bypassed

    HighCVSS 7.1No exploitEPSS 0%

    misskey · misskeyMar 10, 2026

  • Misskey has a login rate limit bypass via spoofed X-Forwarded-For header

    MediumCVSS 6.9No exploitEPSS 0%

    misskey · misskeyDec 15, 2025

  • Missing validation allows spoofed poll updates in Misskey

    MediumCVSS 6.9No exploitEPSS 0%

    misskey · misskeyDec 18, 2024

  • Server-Side Request Forgery vulnerability in misskey

    MediumCVSS 6.5No exploitEPSS 1%

    misskey · misskeySep 7, 2021

  • Misskey before 10.102.4 allows hijacking a user's token.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    misskey · misskeyJul 29, 2019

  • Cross site scripting (XSS) vulnerability using authentication callback in Misskey

    MediumCVSS 6.1No exploitEPSS 0%

    misskey · misskeyFeb 22, 2023

  • Cross site scripting (XSS) of ActivityPub URI in misskey

    MediumCVSS 6.1No exploitEPSS 0%

    misskey · misskeyFeb 22, 2023

  • Cross site scripting (XSS) vulnerability using url preview in Misskey

    MediumCVSS 6.1No exploitEPSS 0%

    misskey · misskeyFeb 22, 2023

  • XSS vulnerability using dialog

    MediumCVSS 5.4No exploitEPSS 1%

    misskey · misskeyAug 27, 2021

  • Misskey CSS Style Injection Vulnerability In `MkUrlPreview`

    MediumCVSS 5.4No exploitEPSS 0%

    misskey · misskeyMay 5, 2025

  • Server-Side Request Forgery vulnerability in various APIs in Misskey

    MediumCVSS 5.4No exploitEPSS 0%

    misskey · misskeyDec 18, 2024