Skip to content
Noroxi

joinmastodon records

42 published records for vendor joinmastodon.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

42 records
  • Mastodon vulnerable to arbitrary file creation through media attachments

    CriticalCVSS 9.9No exploitEPSS 40%

    joinmastodon · mastodonJul 6, 2023

  • Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.

    CriticalCVSS 9.8No exploitEPSS 3%

    joinmastodon · mastodonSep 22, 2019

  • Mastodon Remote user impersonation and takeover

    CriticalCVSS 9.8No exploitEPSS 2%

    joinmastodon · mastodonFeb 1, 2024

  • Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities.

    CriticalCVSS 9.8No exploitEPSS 1%

    joinmastodon · mastodonFeb 3, 2022

  • CVE-2022-2166
    39Monitor

    Improper Restriction of Excessive Authentication Attempts in mastodon/mastodon

    CriticalCVSS 9.8No exploitEPSS 1%

    joinmastodon · mastodonNov 15, 2022

  • Mastodon has improper authorship check on audience extension for existing posts

    HighCVSS 8.2No exploitEPSS 1%

    joinmastodon · mastodonJul 5, 2024

  • Mastodon: Insufficient verification of email addresses

    HighCVSS 8.2No exploitEPSS 0%

    joinmastodon · mastodonApr 23, 2026

  • Mastodon vulnerable to Denial of Service through slow HTTP responses

    HighCVSS 7.5No exploitEPSS 1%

    joinmastodon · mastodonJul 6, 2023

  • Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacke

    HighCVSS 7.5No exploitEPSS 1%

    joinmastodon · mastodonDec 4, 2022

  • Mastodon Invalid Domain Name Normalization vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    joinmastodon · mastodonSep 19, 2023

  • Mastodon vulnerable to Denial of Service from a single post (client/server)

    HighCVSS 7.5No exploitEPSS 1%

    joinmastodon · mastodonJan 21, 2026

  • Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails

    HighCVSS 7.5No exploitEPSS 1%

    joinmastodon · mastodonAug 5, 2025

  • Lack of media type verification of Activity Streams objects allows impersonation of remote accounts

    HighCVSS 7.7No exploitEPSS 1%

    joinmastodon · mastodonFeb 19, 2024

  • Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.

    HighCVSS 7.5No exploitEPSS 0%

    joinmastodon · mastodonNov 18, 2024

  • Mastodon Server-Side Request Forgery vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    joinmastodon · mastodonSep 19, 2023

  • External OpenID Connect Account Takeover by E-Mail Change in mastodon

    HighCVSS 7.4No exploitEPSS 0%

    joinmastodon · mastodonFeb 14, 2024

  • Mastodon has SSRF Protection bypass

    HighCVSS 7.1No exploitEPSS 0%

    joinmastodon · mastodonJan 8, 2026

  • Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database

    MediumCVSS 6.5No exploitEPSS 1%

    joinmastodon · mastodonApr 4, 2023

  • Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)

    MediumCVSS 6.5No exploitEPSS 0%

    joinmastodon · mastodonFeb 4, 2026

  • Mastodon missing length limits on list names, filter names, and filter keywords

    MediumCVSS 6.5No exploitEPSS 0%

    joinmastodon · mastodonJan 21, 2026

  • CVE-2022-0432
    25Monitor

    Prototype Pollution in mastodon/mastodon

    MediumCVSS 6.1Proof of conceptEPSS 4%

    joinmastodon · mastodonFeb 2, 2022

  • Mastodon vulnerable to Cross-site Scripting through oEmbed preview cards

    MediumCVSS 6.1No exploitEPSS 1%

    joinmastodon · mastodonJul 6, 2023

  • Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'

    MediumCVSS 6.1Proof of conceptEPSS 1%

    joinmastodon · mastodonMar 27, 2026

  • In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.

    MediumCVSS 5.9No exploitEPSS 0%

    joinmastodon · mastodonOct 3, 2024

  • app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.

    MediumCVSS 5.3No exploitEPSS 1%

    joinmastodon · mastodonMay 24, 2022