Misskey records
28 published records for vendor misskey.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 71.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-285 Improper Authorization2
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-346 Origin Validation Error1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
The weakness classes this vendor ships most often: where to look.
CWEAll records
28 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-24812No exploit | SQL injection of notes/search-by-tagmisskey · misskey · CWE-89 | Critical9.8 | — | 0.7% | Feb 22, 2023 |
38Monitor | CVE-2023-52139No exploit | Misskey vulnerable to improper authorization when accessing with third-party applicationmisskey · misskey · CWE-285 | Critical9.6 | — | 0.5% | Dec 29, 2023 |
37Monitor | CVE-2025-25306No exploit | Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notesmisskey · misskey · CWE-346 | Critical9.3 | — | 0.2% | Mar 10, 2025 |
36Monitor | CVE-2026-28431No exploit | Misskey lacks proper authorization checks and input validationmisskey · misskey · CWE-285 | Critical9.2 | — | 0.4% | Mar 10, 2026 |
35Monitor | CVE-2024-25636No exploit | Lack of media type verification of Activity Streams objects allows impersonation and takeover of remote accountsmisskey · misskey · CWE-434 | High8.8 | — | 0.7% | Feb 19, 2024 |
35Monitor | CVE-2024-52590No exploit | Missing validation allows spoofed profiles in Misskeymisskey · misskey · CWE-20 | High8.8 | — | 0.4% | Dec 18, 2024 |
35Monitor | CVE-2024-52591No exploit | Missing validation allows spoofed profiles and notes in Misskeymisskey · misskey · CWE-20 | High8.8 | — | 0.3% | Dec 18, 2024 |
32Monitor | CVE-2025-24896No exploit | Misskey allows token to remain valid in cookie after signing outmisskey · misskey · CWE-613 | High8.1 | — | 0.6% | Feb 11, 2025 |
32Monitor | CVE-2025-24897No exploit | Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributesmisskey · misskey · CWE-352 | High8.2 | — | 0.1% | Feb 11, 2025 |
30Monitor | CVE-2023-43793No exploit | Misskey allows users to bypass authentication of Bull dashboardmisskey · misskey · CWE-287 | High7.5 | — | 0.7% | Oct 4, 2023 |
30Monitor | CVE-2025-46559No exploit | Misskey Directory Traversal Vulnerability in AiScript via `Mk:api`misskey · misskey · CWE-22 | High7.5 | — | 0.4% | May 5, 2025 |
30Monitor | CVE-2023-49079No exploit | Misskey's missing signature validation allows arbitrary users to impersonate any remote user.misskey · misskey · CWE-347 | High7.5 | — | 0.4% | Nov 29, 2023 |
30Monitor | CVE-2024-32983No exploit | Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activitiesmisskey · misskey · CWE-863 | High7.5 | — | 0.4% | Jun 3, 2024 |
28Monitor | CVE-2025-66402No exploit | misskey.js's export data contains private post datamisskey · misskey · CWE-862 | High7.1 | — | 0.3% | Dec 15, 2025 |
28Monitor | CVE-2026-28432No exploit | HTTP signature verification can be bypassedmisskey · misskey · CWE-347 | High7.1 | — | 0.2% | Mar 10, 2026 |
27Monitor | CVE-2025-66482No exploit | Misskey has a login rate limit bypass via spoofed X-Forwarded-For headermisskey · misskey · CWE-307 | Medium6.9 | — | 0.3% | Dec 15, 2025 |
27Monitor | CVE-2024-52592No exploit | Missing validation allows spoofed poll updates in Misskeymisskey · misskey · CWE-20 | Medium6.9 | — | 0.3% | Dec 18, 2024 |
26Monitor | CVE-2021-39195No exploit | Server-Side Request Forgery vulnerability in misskeymisskey · misskey · CWE-918 | Medium6.5 | — | 1.1% | Sep 7, 2021 |
24Monitor | CVE-2019-1020010Proof of concept | Misskey before 10.102.4 allows hijacking a user's token.misskey · misskey · CWE-79 | Medium6.1 | — | 1.3% | Jul 29, 2019 |
24Monitor | CVE-2023-24810No exploit | Cross site scripting (XSS) vulnerability using authentication callback in Misskeymisskey · misskey · CWE-79 | Medium6.1 | — | 0.4% | Feb 22, 2023 |
24Monitor | CVE-2023-25154No exploit | Cross site scripting (XSS) of ActivityPub URI in misskeymisskey · misskey · CWE-79 | Medium6.1 | — | 0.4% | Feb 22, 2023 |
24Monitor | CVE-2023-24811No exploit | Cross site scripting (XSS) vulnerability using url preview in Misskeymisskey · misskey · CWE-79 | Medium6.1 | — | 0.4% | Feb 22, 2023 |
21Monitor | CVE-2021-39169No exploit | XSS vulnerability using dialogmisskey · misskey · CWE-79 | Medium5.4 | — | 0.7% | Aug 27, 2021 |
21Monitor | CVE-2025-46340No exploit | Misskey CSS Style Injection Vulnerability In `MkUrlPreview`misskey · misskey · CWE-20 | Medium5.4 | — | 0.2% | May 5, 2025 |
21Monitor | CVE-2024-52579No exploit | Server-Side Request Forgery vulnerability in various APIs in Misskeymisskey · misskey · CWE-20 | Medium5.4 | — | 0.2% | Dec 18, 2024 |
- CVE-2023-2481239Monitor
SQL injection of notes/search-by-tag
CriticalCVSS 9.8No exploitEPSS 1%misskey · misskeyFeb 22, 2023
- CVE-2023-5213938Monitor
Misskey vulnerable to improper authorization when accessing with third-party application
CriticalCVSS 9.6No exploitEPSS 1%misskey · misskeyDec 29, 2023
- CVE-2025-2530637Monitor
Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
CriticalCVSS 9.3No exploitEPSS 0%misskey · misskeyMar 10, 2025
- CVE-2026-2843136Monitor
Misskey lacks proper authorization checks and input validation
CriticalCVSS 9.2No exploitEPSS 0%misskey · misskeyMar 10, 2026
- CVE-2024-2563635Monitor
Lack of media type verification of Activity Streams objects allows impersonation and takeover of remote accounts
HighCVSS 8.8No exploitEPSS 1%misskey · misskeyFeb 19, 2024
- CVE-2024-5259035Monitor
Missing validation allows spoofed profiles in Misskey
HighCVSS 8.8No exploitEPSS 0%misskey · misskeyDec 18, 2024
- CVE-2024-5259135Monitor
Missing validation allows spoofed profiles and notes in Misskey
HighCVSS 8.8No exploitEPSS 0%misskey · misskeyDec 18, 2024
- CVE-2025-2489632Monitor
Misskey allows token to remain valid in cookie after signing out
HighCVSS 8.1No exploitEPSS 1%misskey · misskeyFeb 11, 2025
- CVE-2025-2489732Monitor
Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributes
HighCVSS 8.2No exploitEPSS 0%misskey · misskeyFeb 11, 2025
- CVE-2023-4379330Monitor
Misskey allows users to bypass authentication of Bull dashboard
HighCVSS 7.5No exploitEPSS 1%misskey · misskeyOct 4, 2023
- CVE-2025-4655930Monitor
Misskey Directory Traversal Vulnerability in AiScript via `Mk:api`
HighCVSS 7.5No exploitEPSS 0%misskey · misskeyMay 5, 2025
- CVE-2023-4907930Monitor
Misskey's missing signature validation allows arbitrary users to impersonate any remote user.
HighCVSS 7.5No exploitEPSS 0%misskey · misskeyNov 29, 2023
- CVE-2024-3298330Monitor
Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activities
HighCVSS 7.5No exploitEPSS 0%misskey · misskeyJun 3, 2024
- CVE-2025-6640228Monitor
misskey.js's export data contains private post data
HighCVSS 7.1No exploitEPSS 0%misskey · misskeyDec 15, 2025
- CVE-2026-2843228Monitor
HTTP signature verification can be bypassed
HighCVSS 7.1No exploitEPSS 0%misskey · misskeyMar 10, 2026
- CVE-2025-6648227Monitor
Misskey has a login rate limit bypass via spoofed X-Forwarded-For header
MediumCVSS 6.9No exploitEPSS 0%misskey · misskeyDec 15, 2025
- CVE-2024-5259227Monitor
Missing validation allows spoofed poll updates in Misskey
MediumCVSS 6.9No exploitEPSS 0%misskey · misskeyDec 18, 2024
- CVE-2021-3919526Monitor
Server-Side Request Forgery vulnerability in misskey
MediumCVSS 6.5No exploitEPSS 1%misskey · misskeySep 7, 2021
- CVE-2019-102001024Monitor
Misskey before 10.102.4 allows hijacking a user's token.
MediumCVSS 6.1Proof of conceptEPSS 1%misskey · misskeyJul 29, 2019
- CVE-2023-2481024Monitor
Cross site scripting (XSS) vulnerability using authentication callback in Misskey
MediumCVSS 6.1No exploitEPSS 0%misskey · misskeyFeb 22, 2023
- CVE-2023-2515424Monitor
Cross site scripting (XSS) of ActivityPub URI in misskey
MediumCVSS 6.1No exploitEPSS 0%misskey · misskeyFeb 22, 2023
- CVE-2023-2481124Monitor
Cross site scripting (XSS) vulnerability using url preview in Misskey
MediumCVSS 6.1No exploitEPSS 0%misskey · misskeyFeb 22, 2023
- CVE-2021-3916921Monitor
XSS vulnerability using dialog
MediumCVSS 5.4No exploitEPSS 1%misskey · misskeyAug 27, 2021
- CVE-2025-4634021Monitor
Misskey CSS Style Injection Vulnerability In `MkUrlPreview`
MediumCVSS 5.4No exploitEPSS 0%misskey · misskeyMay 5, 2025
- CVE-2024-5257921Monitor
Server-Side Request Forgery vulnerability in various APIs in Misskey
MediumCVSS 5.4No exploitEPSS 0%misskey · misskeyDec 18, 2024