joinmastodon records
42 published records for vendor joinmastodon.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-770 Allocation of Resources Without Limits or Throttling5
- CWE-863 Incorrect Authorization4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-613 Insufficient Session Expiration3
- CWE-862 Missing Authorization2
- CWE-918 Server-Side Request Forgery (SSRF)2
The weakness classes this vendor ships most often: where to look.
CWEAll records
42 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2023-36460No exploit | Mastodon vulnerable to arbitrary file creation through media attachmentsjoinmastodon · mastodon · CWE-22 | Critical9.9 | — | 40.1% | Jul 6, 2023 |
40Plan | CVE-2018-21018No exploit | Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.joinmastodon · mastodon · CWE-613 | Critical9.8 | — | 2.6% | Sep 22, 2019 |
40Plan | CVE-2024-23832No exploit | Mastodon Remote user impersonation and takeoverjoinmastodon · mastodon · CWE-290 | Critical9.8 | — | 2.5% | Feb 1, 2024 |
39Monitor | CVE-2022-24307No exploit | Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities.joinmastodon · mastodon · CWE-863 | Critical9.8 | — | 1.4% | Feb 3, 2022 |
39Monitor | CVE-2022-2166No exploit | Improper Restriction of Excessive Authentication Attempts in mastodon/mastodonjoinmastodon · mastodon · CWE-307 | Critical9.8 | — | 1.1% | Nov 15, 2022 |
32Monitor | CVE-2024-37903No exploit | Mastodon has improper authorship check on audience extension for existing postsjoinmastodon · mastodon · CWE-862 | High8.2 | — | 0.5% | Jul 5, 2024 |
32Monitor | CVE-2026-41259No exploit | Mastodon: Insufficient verification of email addressesjoinmastodon · mastodon · CWE-841 | High8.2 | — | 0.4% | Apr 23, 2026 |
30Monitor | CVE-2023-36461No exploit | Mastodon vulnerable to Denial of Service through slow HTTP responsesjoinmastodon · mastodon · CWE-770 | High7.5 | — | 1.3% | Jul 6, 2023 |
30Monitor | CVE-2022-46405No exploit | Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attackejoinmastodon · mastodon · CWE-674 | High7.5 | — | 0.9% | Dec 4, 2022 |
30Monitor | CVE-2023-42451No exploit | Mastodon Invalid Domain Name Normalization vulnerabilityjoinmastodon · mastodon · CWE-706 | High7.5 | — | 0.7% | Sep 19, 2023 |
30Monitor | CVE-2026-23962No exploit | Mastodon vulnerable to Denial of Service from a single post (client/server)joinmastodon · mastodon · CWE-770 | High7.5 | — | 0.6% | Jan 21, 2026 |
30Monitor | CVE-2025-54879No exploit | Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emailsjoinmastodon · mastodon · CWE-770 | High7.5 | — | 0.5% | Aug 5, 2025 |
30Monitor | CVE-2024-25623No exploit | Lack of media type verification of Activity Streams objects allows impersonation of remote accountsjoinmastodon · mastodon · CWE-434 | High7.7 | — | 0.5% | Feb 19, 2024 |
30Monitor | CVE-2023-49952No exploit | Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.joinmastodon · mastodon · CWE-79 | High7.5 | — | 0.5% | Nov 18, 2024 |
30Monitor | CVE-2023-42450No exploit | Mastodon Server-Side Request Forgery vulnerabilityjoinmastodon · mastodon · CWE-113 | High7.5 | — | 0.5% | Sep 19, 2023 |
29Monitor | CVE-2024-25618No exploit | External OpenID Connect Account Takeover by E-Mail Change in mastodonjoinmastodon · mastodon · CWE-287 | High7.4 | — | 0.5% | Feb 14, 2024 |
28Monitor | CVE-2026-22245No exploit | Mastodon has SSRF Protection bypassjoinmastodon · mastodon · CWE-918 | High7.1 | — | 0.3% | Jan 8, 2026 |
26Monitor | CVE-2023-28853No exploit | Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP databasejoinmastodon · mastodon · CWE-90 | Medium6.5 | — | 1.3% | Apr 4, 2023 |
26Monitor | CVE-2026-25540No exploit | Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)joinmastodon · mastodon · CWE-524 | Medium6.5 | — | 0.4% | Feb 4, 2026 |
26Monitor | CVE-2026-23963No exploit | Mastodon missing length limits on list names, filter names, and filter keywordsjoinmastodon · mastodon · CWE-770 | Medium6.5 | — | 0.3% | Jan 21, 2026 |
25Monitor | CVE-2022-0432Proof of concept | Prototype Pollution in mastodon/mastodonjoinmastodon · mastodon · CWE-1321 | Medium6.1 | — | 4.4% | Feb 2, 2022 |
24Monitor | CVE-2023-36459No exploit | Mastodon vulnerable to Cross-site Scripting through oEmbed preview cardsjoinmastodon · mastodon · CWE-79 | Medium6.1 | — | 1.2% | Jul 6, 2023 |
24Monitor | CVE-2026-33868Proof of concept | Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'joinmastodon · mastodon · CWE-601 | Medium6.1 | — | 0.6% | Mar 27, 2026 |
23Monitor | CVE-2024-34535No exploit | In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.joinmastodon · mastodon · CWE-444 | Medium5.9 | — | 0.4% | Oct 3, 2024 |
21Monitor | CVE-2022-31263No exploit | app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.joinmastodon · mastodon | Medium5.3 | — | 0.9% | May 24, 2022 |
- CVE-2023-3646051Plan
Mastodon vulnerable to arbitrary file creation through media attachments
CriticalCVSS 9.9No exploitEPSS 40%joinmastodon · mastodonJul 6, 2023
- CVE-2018-2101840Plan
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
CriticalCVSS 9.8No exploitEPSS 3%joinmastodon · mastodonSep 22, 2019
- CVE-2024-2383240Plan
Mastodon Remote user impersonation and takeover
CriticalCVSS 9.8No exploitEPSS 2%joinmastodon · mastodonFeb 1, 2024
- CVE-2022-2430739Monitor
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities.
CriticalCVSS 9.8No exploitEPSS 1%joinmastodon · mastodonFeb 3, 2022
- CVE-2022-216639Monitor
Improper Restriction of Excessive Authentication Attempts in mastodon/mastodon
CriticalCVSS 9.8No exploitEPSS 1%joinmastodon · mastodonNov 15, 2022
- CVE-2024-3790332Monitor
Mastodon has improper authorship check on audience extension for existing posts
HighCVSS 8.2No exploitEPSS 1%joinmastodon · mastodonJul 5, 2024
- CVE-2026-4125932Monitor
Mastodon: Insufficient verification of email addresses
HighCVSS 8.2No exploitEPSS 0%joinmastodon · mastodonApr 23, 2026
- CVE-2023-3646130Monitor
Mastodon vulnerable to Denial of Service through slow HTTP responses
HighCVSS 7.5No exploitEPSS 1%joinmastodon · mastodonJul 6, 2023
- CVE-2022-4640530Monitor
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacke
HighCVSS 7.5No exploitEPSS 1%joinmastodon · mastodonDec 4, 2022
- CVE-2023-4245130Monitor
Mastodon Invalid Domain Name Normalization vulnerability
HighCVSS 7.5No exploitEPSS 1%joinmastodon · mastodonSep 19, 2023
- CVE-2026-2396230Monitor
Mastodon vulnerable to Denial of Service from a single post (client/server)
HighCVSS 7.5No exploitEPSS 1%joinmastodon · mastodonJan 21, 2026
- CVE-2025-5487930Monitor
Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails
HighCVSS 7.5No exploitEPSS 1%joinmastodon · mastodonAug 5, 2025
- CVE-2024-2562330Monitor
Lack of media type verification of Activity Streams objects allows impersonation of remote accounts
HighCVSS 7.7No exploitEPSS 1%joinmastodon · mastodonFeb 19, 2024
- CVE-2023-4995230Monitor
Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.
HighCVSS 7.5No exploitEPSS 0%joinmastodon · mastodonNov 18, 2024
- CVE-2023-4245030Monitor
Mastodon Server-Side Request Forgery vulnerability
HighCVSS 7.5No exploitEPSS 0%joinmastodon · mastodonSep 19, 2023
- CVE-2024-2561829Monitor
External OpenID Connect Account Takeover by E-Mail Change in mastodon
HighCVSS 7.4No exploitEPSS 0%joinmastodon · mastodonFeb 14, 2024
- CVE-2026-2224528Monitor
Mastodon has SSRF Protection bypass
HighCVSS 7.1No exploitEPSS 0%joinmastodon · mastodonJan 8, 2026
- CVE-2023-2885326Monitor
Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
MediumCVSS 6.5No exploitEPSS 1%joinmastodon · mastodonApr 4, 2023
- CVE-2026-2554026Monitor
Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)
MediumCVSS 6.5No exploitEPSS 0%joinmastodon · mastodonFeb 4, 2026
- CVE-2026-2396326Monitor
Mastodon missing length limits on list names, filter names, and filter keywords
MediumCVSS 6.5No exploitEPSS 0%joinmastodon · mastodonJan 21, 2026
- CVE-2022-043225Monitor
Prototype Pollution in mastodon/mastodon
MediumCVSS 6.1Proof of conceptEPSS 4%joinmastodon · mastodonFeb 2, 2022
- CVE-2023-3645924Monitor
Mastodon vulnerable to Cross-site Scripting through oEmbed preview cards
MediumCVSS 6.1No exploitEPSS 1%joinmastodon · mastodonJul 6, 2023
- CVE-2026-3386824Monitor
Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'
MediumCVSS 6.1Proof of conceptEPSS 1%joinmastodon · mastodonMar 27, 2026
- CVE-2024-3453523Monitor
In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
MediumCVSS 5.9No exploitEPSS 0%joinmastodon · mastodonOct 3, 2024
- CVE-2022-3126321Monitor
app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.
MediumCVSS 5.3No exploitEPSS 1%joinmastodon · mastodonMay 24, 2022