Vulnerabilidades em LemmyNet
12 resultadosAnálise Vexday
LemmyNet apresenta 6 vulnerabilidades catalogadas sem ocorrência de ataques ativos registrados, reduzindo o risco imediato de exploração. A fraqueza dominante é requisição Server-Side falha (CWE-918), padrão em aplicações web, com 2 novas vulnerabilidades divulgadas nos últimos 90 dias indicando atividade contínua de descoberta. O perfil sugere risco moderado e monitoramento regular, mas sem indicadores de exploração em massa.
CVE-2026-54742MEDIUMLemmy: `CollectionAdd::Featured` does not check the post is in the communityEPSS 0.5%CVE-2026-54743MEDIUMLemmy: Stored XSS via markdown image alt-text in lemmy-ui html5-embedEPSS 0.5%CVE-2024-23649HIGHAny authenticated user may obtain private message details from other users on the same instanceEPSS 0.5%CVE-2026-54741MEDIUMLemmy: Blocked users can edit private messages sent before the blockEPSS 0.4%CVE-2026-54739MEDIUMLemmy: Login Endpoint User Enumeration via HTTP Response Code DifferentialEPSS 0.4%CVE-2026-54738MEDIUMLemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfoEPSS 0.4%CVE-2025-25194MEDIUMServer-Side Request Forgery (SSRF) in activitypub_federationEPSS 0.4%CVE-2026-54740MEDIUMLemmy: Lower-ranked federated moderator can remove higher-ranked moderatorsEPSS 0.4%CVE-2026-33693MEDIUMLemmy's Activitypub-Federation has SSRF via 0.0.0.0 bypass in activitypub-federation-rust v4_is_invalid()EPSS 0.4%CVE-2026-29178HIGHLemmy: Unauthenticated SSRF via file_type query parameter injection in image endpointEPSS 0.3%CVE-2026-42181MEDIUMLemmy: SSRF and internal image disclosure in post link metadata via unvalidated og:imageEPSS 0.2%CVE-2026-42180MEDIUMLemmy: SSRF in /api/v3/post via Webmention dispatchEPSS 0.2%