Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Joinmastodon

First CVE: Sep 22, 2019Active for: 7 yearsTotal CVEs: 42
46.6
VTI Score
High

Mastodon, the widely deployed open-source social media platform, carries a concentrated vulnerability footprint that skews toward serious outcomes with a meaningful share reaching critical severity. The exposure centers on a single product and recurs through weakness classes characteristic of web applications handling user input and session state: resource exhaustion without throttling, authorization bypasses, cross-site scripting, and insufficient session expiration. These flaw patterns reflect the platform's role as an internet-facing service processing untrusted user-supplied content and managing authentication across distributed federated instances. Defenders running Mastodon instances should prioritize patching releases closely, as the platform's public deployment and federation model make it an attractive target; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
42
Total CVEs
More Total CVEs than 98% of tracked vendors
7.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Joinmastodon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2019
6 years ago
Most Recent CVE
Apr 23, 2026
92 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (42 CVEs).

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-36460CRITICAL
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully craft
Jul 6, 20239.955NONO
CVE-2024-23832CRITICAL
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Ma
Feb 1, 20249.835NONO
CVE-2022-24307CRITICAL
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since
Feb 3, 20229.832NONO
CVE-2026-33868MEDIUM
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) ex
Mar 27, 20266.131NOYES
CVE-2018-21018CRITICAL
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
Sep 22, 20199.830NONO
CVE-2026-27468HIGH
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5
Feb 24, 20268.228NONO
CVE-2026-23962HIGH
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll
Jan 22, 20267.528NONO
CVE-2026-23963MEDIUM
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names
Jan 22, 20266.526NONO
CVE-2026-22245HIGH
Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has
Jan 8, 20267.526NONO
CVE-2022-0432MEDIUM
Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.
Feb 2, 20226.126NOYES
View all 42 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products42 CVEs
52%
31%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network42 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (88.1%)
High5 (11.9%)
Unknown0 (0.0%)
User Interaction
None36 (85.7%)
Unknown0 (0.0%)
Required6 (14.3%)
Privileges Required
Low14 (33.3%)
High0 (0.0%)
None28 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (42 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
4.8% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Joinmastodon.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Joinmastodon — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Joinmastodon's Products

View all 3 CNAs →

Top CWEs