Exposure of Mattermost
Message boards44
exposure score
2
sites use
0
exploited
6
critical
CVEs
454 resultsCVE-2026-11993MEDIUMFix authenticated members disabling file content indexing server-wide via extraction pool exhaustionEPSS 0.2%CVE-2026-12882MEDIUMMattermost Markdown autolink parsing denial of serviceEPSS 0.2%CVE-2026-13417MEDIUMBoards plugin denial of service via unvalidated block fields.propertiesEPSS 0.2%CVE-2026-9812MEDIUMMissing property field ownership validation in Playbooks run property update endpointEPSS 0.2%CVE-2024-39767MEDIUMSpoofed push notifications from malicious serverEPSS 0.2%CVE-2025-27933MEDIUMUnauthorized Private-to-Public Channel ConversionEPSS 0.2%CVE-2026-20796LOWTime-of-check time-of-use vulnerability in common teams APIEPSS 0.2%CVE-2025-13821MEDIUMUser profile update exposes password hash and MFA secretsEPSS 0.2%CVE-2026-5163MEDIUMMissing authorization check in AI message rewrite endpoint allows access to private thread contentEPSS 0.2%CVE-2025-2571MEDIUMGoogle OAuth Authentication Bypass for Converted Bot AccountsEPSS 0.2%CVE-2024-45835LOWInsufficient Electron Fuses ConfigurationEPSS 0.2%CVE-2026-1629MEDIUMPermalink Preview Information Disclosure After Permission RevocationEPSS 0.2%CVE-2025-53971LOWChannel and Team Membership APIs inadvertently allow loss of Member privileges.EPSS 0.2%CVE-2025-49810LOWThread summarization allows persistent access to channelEPSS 0.2%CVE-2025-46702MEDIUMMattermost Playbooks allows privilege escalation through improper access control in playbook run participant managementEPSS 0.2%CVE-2024-40886MEDIUMOne-click Client-Side Path Traversal Leading to CSRF in User Management admin pageEPSS 0.2%CVE-2026-8683MEDIUMOverly long URLs crash the Mattermost Desktop AppEPSS 0.2%CVE-2025-13324LOWLack of Invalidation of Legacy Remote Cluster Invite Tokens After ConfirmationEPSS 0.2%CVE-2026-16045LOWDelegated OAuth tokens could revoke unrelated OAuth application authorizationsEPSS 0.2%CVE-2025-11776MEDIUMGuest user can discover archived public channelsEPSS 0.2%