Exposure of Mattermost
Message boards52
exposure score
1
sites use
0
exploited
6
critical
CVEs
421 resultsCVE-2026-4273LOWInsufficient token rotation validation in remote cluster invite confirmationEPSS 0.1%CVE-2025-59480MEDIUMInadequate validation of SSO redirect credentials permits credential theftEPSS 0.1%CVE-2026-9597MEDIUMDeactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpointEPSS 0.1%CVE-2026-4274MEDIUMInsufficient authorization in shared channel membership sync grants team-level access instead of channel-level accessEPSS 0.1%CVE-2025-9078MEDIUMWeak cache keys lead to post IDOR and link preview poisoningEPSS 0.1%CVE-2026-28735MEDIUMGitHub OAuth Scope ValidationEPSS 0.1%CVE-2026-6333LOWSSRF via Host Header Spoofing in Custom Slash CommandsEPSS 0.1%CVE-2026-1628MEDIUMMattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.EPSS 0.1%CVE-2025-62690LOWOpen redirect in error page when link opened in new tabEPSS 0.1%CVE-2026-28741MEDIUMCSRF Protection Bypass Allows Updating a User's Authentication MethodEPSS 0.1%CVE-2026-3113MEDIUMmmctl export download command doesn’t restrict permissions to created file to file ownerEPSS 0.1%CVE-2024-11358MEDIUMInsecure Android File Provider PathsEPSS 0.1%CVE-2026-27659MEDIUMCSRF vulnerability in UpdateAccessControlPolicyActiveStatus endpointEPSS 0.1%CVE-2026-6334LOWOAuth authorization code client binding not enforced during token redemption in MattermostEPSS 0.1%CVE-2026-22880MEDIUMMobile SSO authentication flow allows credential theft via malicious serverEPSS 0.1%CVE-2026-6339MEDIUMMissing request origin validation on burn-on-read reveal endpointEPSS 0.1%CVE-2026-2457MEDIUMWebSocket Message Spoofing via Permalink Embed ManipulationEPSS 0.1%CVE-2025-13321LOWMattermost Desktop App logging sensitive information and fails to clear data on server deletionEPSS 0.1%CVE-2026-4339MEDIUMSSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP serverEPSS 0.1%CVE-2025-62190MEDIUMCSRF Allows Call Initiation and Message DeliveryEPSS 0.1%