Pixelfed is a federated, open-source social media platform whose vulnerability profile centers on its core application and recurs through authorization and access-control weaknesses, including improper authorization checks, exposure of sensitive information, and insufficient privilege handling. These patterns reflect common risks in web applications that manage user-generated content and federated identity; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pixelfed over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25108HIGH Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functiona | Feb 12, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-0914MEDIUM Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4. | Feb 19, 2023 | 5.3 | 20 | NO | NO |
CVE-2023-0901MEDIUM Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4. | Feb 18, 2023 | 5.3 | 19 | NO | NO |
CVE-2025-30741MEDIUM Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise h | Mar 25, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pixelfed.
Media articles that mention a CVE ID that affects a product developed by Pixelfed — matched by CVE ID, not by vendor name.