Claire
31 exploits
Active since Jul 2023
Mastodon 2.6.0-4.1.18 - Unauthorized Post Audience Extension via Crafted Activities
CVSS 8.2
Mastodon <4.1.23-4.3.4 - Info Disclosure
CVSS 5.3
Mastodon 4.4.0-4.4.7 - Quote Control Bypass via Reblog
CVSS 4.3
Mastodon < 4.2.29 - Server-Side Request Forgery via IP Address Range Bypass
CVSS 7.5
Mastodon < 4.3.17 - Unauthenticated Information Disclosure via Severed Relationship Notifications
CVSS 6.5
Mastodon < 4.2.29 - Server-Side Request Forgery via IP Address Range Bypass
CVSS 7.5
Mastodon < 4.3.17 - Unauthenticated Information Disclosure via Severed Relationship Notifications
CVSS 6.5
Mastodon 1.3-3.5.8 - Stored Cross-Site Scripting via oEmbed Preview Card
CVSS 9.3
Mastodon <3.5.9, <4.0.5, <4.1.3 - Remote Code Execution
CVSS 9.9
Mastodon < 3.5.9 - Denial of Service via Slowloris HTTP Response
CVSS 7.5
Mastodon 2.6.0-3.5.8 - URL Spoofing via Verified Profile Link Formatting
CVSS 5.4
Mastodon 4.2.0-beta1 to 4.2.0-rc1 - HTTP Request Injection
CVSS 5.4
Mastodon <3.5.14, <4.0.10, <4.1.8, <4.2.0-rc2 - Open Redirect
CVSS 7.4
Mastodon 4.0.0-4.0.9 - Cross-Site Scripting via Translation Feature
CVSS 6.1
Mastodon < 3.5.17, 4.0.x < 4.0.13, 4.1.x < 4.1.13, 4.2.x < 4.2.5 - Authentication Bypass via LDAP Origin Validation
CVSS 9.4
Mastodon < 3.5.18 - Account Takeover via External Authentication Provider Email Matching
CVSS 4.2
Mastodon < 3.5.18 - Insufficient Session Expiration via OAuth Application Destruction
CVSS 3.1
Mastodon <4.2.7, 4.1.15, 4.0.15, 3.5.19 - Info Disclosure
CVSS 8.5
Mastodon 2.6.0-4.1.18 - Unauthorized Post Audience Extension via Crafted Activities
CVSS 8.2
CreateWiki >=2018-11-07 <2024-10-07 - Stored Cross-Site Scripting in Wiki Request Queue
CVSS 6.1
WikiDiscover < 2024-10-06 - Stored Cross-Site Scripting in Special:WikiDiscover Page
CVSS 7.6
ImportDump - Stored Cross-Site Scripting in Special:RequestImportQueue Date Messages
CVSS 6.0
IncidentReporting - Authenticated Cross-Site Scripting
CVSS 6.0
Mediawiki Extension - Info Disclosure
CVSS 6.4
Mastodon <4.2.16-4.3.4 - Info Disclosure
CVSS 5.3