Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
Packagist/pixelfed/pixelfed — 4 CVEs · VulnScope
pkg:Packagist/
pixelfed/pixelfed
4 total CVEs
CRITICAL
1
MEDIUM
3
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.9
CVE-2024-25108
Pixelfed doesn't check OAuth Scopes in API routes, giving elevated permissions
>= 0.10.4, < 0.11.11
MEDIUM
5.3
CVE-2023-0914
Pixelfed may allow unauthorized actor to view private posts
from 0, <= 0.11.4
MEDIUM
5.3
CVE-2023-0901
Pixelfed allows user enumeration via reset password functionality
from 0, <= 0.11.4
MEDIUM
4.3
Pixelfed may allow unauthorized actor to view private posts and private users
from 0, < 0.12.5
CVE-2025-30741