vciy

CVEs we hold for Misskey-dev

Records whose assigning authority named Misskey-dev as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-57575Misskey: SSRF bypass in URL Previewmisskey-dev misskey
CVE-2026-57574Misskey: TOTP tokens can be reusedmisskey-dev misskey
CVE-2026-48115Misskey: Improper Authorization in the Announcements APImisskey-dev misskey
CVE-2026-47746Misskey: JSON-LD signature validation + compaction is vulnerable to timing attacksmisskey-dev misskey
CVE-2026-46714Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilationmisskey-dev misskey
CVE-2026-46713Misskey: JSON-LD signature validation + compaction may lead to improper activity handlingmisskey-dev misskey
CVE-2026-46712Misskey: Lack of proper permission checks in Direct Messaging featuremisskey-dev misskey
CVE-2026-28433Misskey lacks resource ownership validationmisskey-dev misskey
CVE-2026-28432HTTP signature verification can be bypassedmisskey-dev misskey
CVE-2026-28431Misskey lacks proper authorization checks and input validationmisskey-dev misskey
CVE-2025-66482Misskey has a login rate limit bypass via spoofed X-Forwarded-For headermisskey-dev misskey
CVE-2025-66402misskey.js's export data contains private post datamisskey-dev misskey
CVE-2025-46559Misskey Directory Traversal Vulnerability in AiScript via `Mk:api`misskey-dev misskey
CVE-2025-46553@misskey-dev/summaly Redirect Filter Bypassmisskey-dev summaly
CVE-2025-46340Misskey CSS Style Injection Vulnerability In `MkUrlPreview`misskey-dev misskey
CVE-2025-25306Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notesmisskey-dev misskey
CVE-2025-24897Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributesmisskey-dev misskey
CVE-2025-24896Misskey allows token to remain valid in cookie after signing outmisskey-dev misskey
CVE-2024-52593Missing validation allows spoofed "origin" links in Misskeymisskey-dev misskey
CVE-2024-52592Missing validation allows spoofed poll updates in Misskeymisskey-dev misskey
CVE-2024-52591Missing validation allows spoofed profiles and notes in Misskeymisskey-dev misskey
CVE-2024-52590Missing validation allows spoofed profiles in Misskeymisskey-dev misskey
CVE-2024-52579Server-Side Request Forgery vulnerability in various APIs in Misskeymisskey-dev misskey
CVE-2024-49363Uncontrolled Recursion and Asymmetric Resource Consumption (Amplification) in media/file proxy in Misskeymisskey-dev misskey
CVE-2024-32983Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activitiesmisskey-dev misskey
CVE-2024-25636Lack of media type verification of Activity Streams objects allows impersonation and takeover of remote accountsmisskey-dev misskey
CVE-2023-52139Misskey vulnerable to improper authorization when accessing with third-party applicationmisskey-dev misskey
CVE-2023-49079Misskey's missing signature validation allows arbitrary users to impersonate any remote user.misskey-dev misskey
CVE-2023-43793Misskey allows users to bypass authentication of Bull dashboardmisskey-dev misskey
CVE-2023-25154Cross site scripting (XSS) of ActivityPub URI in misskeymisskey-dev misskey
CVE-2023-24812SQL injection of notes/search-by-tagmisskey-dev misskey
CVE-2023-24811Cross site scripting (XSS) vulnerability using url preview in Misskeymisskey-dev misskey
CVE-2023-24810Cross site scripting (XSS) vulnerability using authentication callback in Misskeymisskey-dev misskey
CVE-2021-39195Server-Side Request Forgery vulnerability in misskeymisskey-dev misskey
CVE-2021-39169XSS vulnerability using dialogmisskey-dev misskey

35 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.