Exposure of Mattermost

Message boards
52
exposure score
1
sites use
0
exploited
6
critical

CVEs

421 results
CVE-2025-27936MEDIUMWebhook Secret Exposure via Timing attack in MSteams pluginEPSS 0.3%CVE-2023-1774MEDIUMUnauthorized email invite to a private channelEPSS 0.3%CVE-2023-6547LOWPlaybooks access/modification by removed team memberEPSS 0.3%CVE-2025-6226MEDIUMIDOR in CreatePost API allows for timeboxed message disclosureEPSS 0.3%CVE-2025-58075HIGHArbitrary Mattermost Team can be joined by manipulating the SAML RelayStateEPSS 0.3%CVE-2024-24776LOW Incorrect Authorization leads to Channel Member Count LeakEPSS 0.3%CVE-2024-23488LOWFiles of archived channels accessible with the “Allow users to view archived channels” option disabledEPSS 0.3%CVE-2025-31947MEDIUMRepeated LDAP login failures can lock an LDAP accountEPSS 0.3%CVE-2024-39772LOWSilent Desktop Screenshot CaptureEPSS 0.3%CVE-2026-21388LOWUnbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook EndpointEPSS 0.3%CVE-2026-24661LOWUnbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook EndpointEPSS 0.3%CVE-2024-21848LOWUsers maintain access to active call after being removed from a channelEPSS 0.3%CVE-2026-7387HIGHMattermost group syncable endpoints allow privilege escalation via scheme_adminEPSS 0.3%CVE-2023-45316HIGHReflected client side path traversal leading to CSRF in PlaybooksEPSS 0.3%CVE-2023-4106MEDIUMA guest user can perform various actions on public playbooksEPSS 0.3%CVE-2024-2445MEDIUMReflected XSS in Mattermost Jira pluginEPSS 0.3%CVE-2026-6961HIGHCVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation syncEPSS 0.3%CVE-2026-26233MEDIUMDenial of Service via HTTP/2 single packet attack on login endpointEPSS 0.3%CVE-2025-2570LOWSystem Admin Cannot Access Environment settings in System Console While System Manager CanEPSS 0.3%CVE-2024-36257LOWLack of permission check when updating the profile picture of a remote user (shared channels enabled)EPSS 0.3%