Exposure of Mattermost
Message boards47
exposure score
2
sites use
0
exploited
6
critical
CVEs
454 resultsCVE-2025-3611LOWImproper Access Control in Mattermost allows System Managers to view team details despite role restrictionsEPSS 0.2%CVE-2024-2447MEDIUMMattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of cEPSS 0.2%CVE-2025-4128LOWMattermost Guest User Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-24839LOWUnauthorized AI bot activation via Wrangler pluginEPSS 0.2%CVE-2024-42406MEDIUMUnauthorized access on archived channelsEPSS 0.2%CVE-2026-26246MEDIUMMemory Exhaustion via Malformed PSD File UploadEPSS 0.2%CVE-2025-13870LOWUnauthorized access and subscription vulnerability in BoardsEPSS 0.2%CVE-2024-32939MEDIUMEmail addresses of remote users visible in props regardless of server settingsEPSS 0.2%CVE-2025-47870MEDIUMTeam invite ID leaked to team admin with no member invite privilegesEPSS 0.2%CVE-2025-3230MEDIUMBypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost ServerEPSS 0.2%CVE-2026-2578MEDIUMInformation Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read PostsEPSS 0.2%CVE-2026-4265MEDIUMGuest user can upload files without permission across teamsEPSS 0.2%CVE-2026-16049LOW_GitLab Plugin allows cross-channel post injection and phishing via missing channel permission checks in issue API endpoints_EPSS 0.2%CVE-2026-86349MEDIUMMattermost Server Algorithmic DoS via Unbounded Markdown Block NestingEPSS 0.2%CVE-2026-10600MEDIUMDenial of service via unbounded document content extraction in Mattermost ServerEPSS 0.2%CVE-2026-86348MEDIUMMS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin processEPSS 0.2%CVE-2024-45843LOWWeak SSRF FilteringEPSS 0.2%CVE-2025-12559MEDIUMInformation Disclosure in Common Teams APIEPSS 0.2%CVE-2024-36250LOWMFA Code ReplayEPSS 0.2%CVE-2026-12882MEDIUMMattermost Markdown autolink parsing denial of serviceEPSS 0.2%