VendorsMisskeymisskeyall versions
Vulnerabilities

Misskey Misskey

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2023-24812
SQL injection of notes/search-by-tag
Published 2023-02-22 · Modified
9.8EPSS 0.007
CVE-2023-52139
Misskey vulnerable to improper authorization when accessing with third-party application
Published 2023-12-29 · Modified
9.6EPSS 0.005
CVE-2023-49079
Misskey's missing signature validation allows arbitrary users to impersonate any remote user.
Published 2023-11-29 · Modified
9.3EPSS 0.004
CVE-2024-52591
Missing validation allows spoofed profiles and notes in Misskey
Published 2024-12-18 · Analyzed
9.3EPSS 0.003
CVE-2025-25306
Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
Published 2025-03-10 · Analyzed
9.3EPSS 0.002
CVE-2026-28431
Misskey lacks proper authorization checks and input validation
Published 2026-03-09 · Analyzed
9.2EPSS 0.004
CVE-2024-25636
Lack of media type verification of Activity Streams objects allows impersonation and takeover of remote accounts
Published 2024-02-19 · Analyzed
8.8EPSS 0.007
CVE-2024-52590
Missing validation allows spoofed profiles in Misskey
Published 2024-12-18 · Analyzed
8.8EPSS 0.004
CVE-2024-32983
Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activities
Published 2024-06-03 · Analyzed
8.2EPSS 0.004
CVE-2025-24897
Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributes
Published 2025-02-11 · Analyzed
8.2EPSS 0.001
CVE-2025-24896
Misskey allows token to remain valid in cookie after signing out
Published 2025-02-11 · Analyzed
8.1EPSS 0.006
CVE-2021-39169
XSS vulnerability using dialog
Published 2021-08-27 · Modified
8.0EPSS 0.007
CVE-2021-39195
Server-Side Request Forgery vulnerability in misskey
Published 2021-09-07 · Modified
7.7EPSS 0.011
CVE-2023-43793
Misskey allows users to bypass authentication of Bull dashboard
Published 2023-10-04 · Modified
7.5EPSS 0.007
CVE-2025-46559
Misskey Directory Traversal Vulnerability in AiScript via `Mk:api`
Published 2025-05-05 · Analyzed
7.5EPSS 0.004
CVE-2026-28432
HTTP signature verification can be bypassed
Published 2026-03-09 · Analyzed
7.5EPSS 0.002
CVE-2025-46340
Misskey CSS Style Injection Vulnerability In `MkUrlPreview`
Published 2025-05-05 · Analyzed
7.2EPSS 0.002
CVE-2023-24810
Cross site scripting (XSS) vulnerability using authentication callback in Misskey
Published 2023-02-22 · Modified
7.1EPSS 0.004
CVE-2023-25154
Cross site scripting (XSS) of ActivityPub URI in misskey
Published 2023-02-22 · Modified
7.1EPSS 0.004
CVE-2023-24811
Cross site scripting (XSS) vulnerability using url preview in Misskey
Published 2023-02-22 · Modified
7.1EPSS 0.004
CVE-2025-66402
misskey.js's export data contains private post data
Published 2025-12-15 · Analyzed
7.1EPSS 0.003
CVE-2025-66482
Misskey has a login rate limit bypass via spoofed X-Forwarded-For header
Published 2025-12-15 · Analyzed
6.9EPSS 0.003
CVE-2024-52592
Missing validation allows spoofed poll updates in Misskey
Published 2024-12-18 · Analyzed
6.9EPSS 0.003
CVE-2024-52579
Server-Side Request Forgery vulnerability in various APIs in Misskey
Published 2024-12-18 · Analyzed
6.4EPSS 0.002
CVE-2019-1020010
Misskey before 10.102.4 allows hijacking a user's token.
Published 2019-07-29 · Modified
6.1EPSS 0.013
CVE-2024-52593
Missing validation allows spoofed "origin" links in Misskey
Published 2024-12-18 · Analyzed
5.3EPSS 0.004
CVE-2026-28433
Misskey lacks resource ownership validation
Published 2026-03-09 · Analyzed
4.3EPSS 0.003