Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

mastodon — Vulnerabilities & Security Advisories 44

All 44 CVE vulnerabilities found in mastodon, with AI-generated Chinese analysis, references, and POCs.

This page aggregates historical vulnerability advisories for the Mastodon social network platform, focusing on specific software components and general security weakness classes associated with the product. The collection documents reported security flaws, including remote code execution, cross-site scripting, and access control issues, spanning the period from initial open-source releases through recent maintenance patches. Readers can use this index to track vendor-issued security bulletins, analyze recurring weakness patterns, and review the complete vulnerability history for the Mastodon codebase. The entries are organized chronologically and by Common Weakness Enumeration identifiers, allowing security teams to identify trends and assess risk exposure across different versions of the application. No individual vulnerability identifiers are highlighted; instead, the focus remains on categorizing and correlating the defects to support broader security posture analysis.

Vendor: mastodon

CVE ID Title CVSS Severity Published
CVE-2025-27157 Mastodon's rate-limits are missing on `/auth/setup` CWE-770 5.3 Medium 2025-02-27
CVE-2024-37903 Mastodon has improper authorship check on audience extension for existing posts CWE-862 8.2 High 2024-07-05
CVE-2024-25623 Lack of media type verification of Activity Streams objects allows impersonation of remote accounts CWE-434 8.5 High 2024-02-19
CVE-2024-25619 Destroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed in mastodon CWE-613 3.1 Low 2024-02-14
CVE-2024-25618 External OpenID Connect Account Takeover by E-Mail Change in mastodon CWE-287 4.2 Medium 2024-02-14
CVE-2024-23832 Mastodon Remote user impersonation and takeover CWE-290 9.4 Critical 2024-02-01
CVE-2023-42452 Mastodon vulnerable to Stored XSS through the translation feature CWE-79 6.1 Medium 2023-09-19
CVE-2023-42451 Mastodon Invalid Domain Name Normalization vulnerability CWE-706 7.4 High 2023-09-19
CVE-2023-42450 Mastodon Server-Side Request Forgery vulnerability CWE-918 5.4 Medium 2023-09-19
CVE-2023-36462 Mastodon's verified profile links can be formatted in a misleading way CWE-20 5.4 Medium 2023-07-06
CVE-2023-36461 Mastodon vulnerable to Denial of Service through slow HTTP responses CWE-770 7.5 High 2023-07-06
CVE-2023-36460 Mastodon vulnerable to arbitrary file creation through media attachments CWE-22 10.0 Critical 2023-07-06
CVE-2023-36459 Mastodon vulnerable to Cross-site Scripting through oEmbed preview cards CWE-79 9.3 Critical 2023-07-06
CVE-2023-28853 Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database CWE-90 7.7 High 2023-04-04

All 44 known CVE vulnerabilities affecting mastodon with full Chinese analysis, references, and POCs where available.