syuilo
7 exploits
Active since Aug 2021
Misskey < 12.51.0 - Cross-Site Scripting via Web Client Dialog
CVSS 8.0
Misskey < 13.3.2 - Cross-Site Scripting via URL Preview Function
CVSS 7.1
Misskey < 13.3.3 - SQL Injection via Notes Search by Tag API
CVSS 8.8
Misskey < 2023.9.0 - Unauthenticated Authentication Bypass via URL Manipulation
CVSS 7.5
Nexkey <12.23Q4.5 - Privilege Escalation
CVSS 8.9
Misskey < 2024.2.0 - Account Takeover via Unrestricted Activity Streams Document Upload
CVSS 7.1
Misskey < 2024.5.0 - Activity Spoofing via Improper JSON Normalization
CVSS 8.2