Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: wordpressPackages.plugins.simple-mastodon-verification

Found 3 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-93485
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 4 days, 14 hours ago Activity log
  • Created suggestion
WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.

Affected products

WordPress
  • =<4.8.30
  • =<5.8.15
  • =<4.9.31
  • =<6.0.14
  • =<6.3.10
  • =<6.7.7
  • =<5.7.17
  • =<5.4.21
  • =<6.9.7
  • =<5.6.19
  • =<5.5.20
  • =<5.3.23
  • =<5.0.27
  • =<5.9.16
  • =<6.1.12
  • =<5.1.24
  • =<6.4.10
  • =<7.0.4
  • =<6.6.7
  • =<6.5.10
  • =<6.8.8
  • =<5.2.26
  • =<6.2.11
  • =<4.7.35
  • <7.1.1

Matching in nixpkgs

pkgs.wordpress

Open source software you can use to create a beautiful website, blog, or app

  • nixos-unstable -
    • nixos-unstable-small 7.1.1
  • nixos-26.05 -
    • nixos-26.05-small 6.9.8

pkgs.wordpress_6_9

Open source software you can use to create a beautiful website, blog, or app

  • nixos-unstable -
    • nixos-unstable-small 6.9.8
  • nixos-26.05 -
    • nixos-26.05-small 6.9.8

pkgs.wordpress_7_0

Open source software you can use to create a beautiful website, blog, or app

  • nixos-unstable -
    • nixos-unstable-small 7.0.5
  • nixos-26.05 -
    • nixos-26.05-small 7.0.5

pkgs.wordpress_7_1

Open source software you can use to create a beautiful website, blog, or app

  • nixos-unstable -
    • nixos-unstable-small 7.1.1
  • nixos-26.05 -
    • nixos-26.05-small 7.1.1

Package maintainers

created 4 months, 4 weeks ago Activity log
  • Created suggestion
Mastodon: Insufficient verification of email addresses

Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that are interpreted differently by some mailing servers. This vulnerability is fixed in v4.5.9, v4.4.16, and v4.3.22.

Affected products

mastodon
  • ==>= 4.4.0-beta.1, < 4.4.16
  • ==>= 4.5.0-beta.1, < 4.5.9
  • ==< 4.3.22

Matching in nixpkgs

pkgs.mastodon

Self-hosted, globally interconnected microblogging software based on ActivityPub

  • nixos-unstable -
    • nixos-unstable-small 4.6.8
  • nixos-26.05 -
    • nixos-26.05-small 4.6.8

pkgs.bitlbee-mastodon

Bitlbee plugin for Mastodon

  • nixos-unstable -
    • nixos-unstable-small 1.4.5
  • nixos-26.05 -
    • nixos-26.05-small 1.4.5

pkgs.mastodon-archive

Utility for backing up your Mastodon content

  • nixos-unstable -
    • nixos-unstable-small 1.4.8
  • nixos-26.05 -
    • nixos-26.05-small 1.4.8

Package maintainers

Permalink CVE-2026-33869
4.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 5 months, 3 weeks ago Activity log
  • Created suggestion
Mastodon has a denial of service for quote authorization

Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on that server. The vulnerability has been patched in Mastodon 4.5.8 and 4.4.15. Mastodon 4.3 and earlier are not affected because they do not support quotes.

Affected products

mastodon
  • ==>= 4.4.0, < 4.4.15
  • ==>= 4.5.0, < 4.5.8

Matching in nixpkgs

pkgs.mastodon

Self-hosted, globally interconnected microblogging software based on ActivityPub

  • nixos-unstable -
    • nixos-unstable-small 4.6.8
  • nixos-26.05 -
    • nixos-26.05-small 4.6.8

pkgs.bitlbee-mastodon

Bitlbee plugin for Mastodon

  • nixos-unstable -
    • nixos-unstable-small 1.4.5
  • nixos-26.05 -
    • nixos-26.05-small 1.4.5

pkgs.mastodon-archive

Utility for backing up your Mastodon content

  • nixos-unstable -
    • nixos-unstable-small 1.4.8
  • nixos-26.05 -
    • nixos-26.05-small 1.4.8

Package maintainers