Exposure of Mattermost
Message boards44
exposure score
2
sites use
0
exploited
6
critical
CVEs
454 resultsCVE-2026-12284LOWMattermost Desktop App Missing IPC Sender Validation in Calls Leave HandlerEPSS 0.1%CVE-2026-28741MEDIUMCSRF Protection Bypass Allows Updating a User's Authentication MethodEPSS 0.1%CVE-2026-10542MEDIUMPlaybooks channel action update validation issueEPSS 0.1%CVE-2026-3113MEDIUMmmctl export download command doesn’t restrict permissions to created file to file ownerEPSS 0.1%CVE-2026-27659MEDIUMCSRF vulnerability in UpdateAccessControlPolicyActiveStatus endpointEPSS 0.1%CVE-2024-11358MEDIUMInsecure Android File Provider PathsEPSS 0.1%CVE-2025-62190MEDIUMCSRF Allows Call Initiation and Message DeliveryEPSS 0.1%CVE-2025-13321LOWMattermost Desktop App logging sensitive information and fails to clear data on server deletionEPSS 0.1%CVE-2026-6334LOWOAuth authorization code client binding not enforced during token redemption in MattermostEPSS 0.1%CVE-2026-22880MEDIUMMobile SSO authentication flow allows credential theft via malicious serverEPSS 0.1%CVE-2025-13326LOWMattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App StoreEPSS 0.1%CVE-2026-6339MEDIUMMissing request origin validation on burn-on-read reveal endpointEPSS 0.1%CVE-2026-2457MEDIUMWebSocket Message Spoofing via Permalink Embed ManipulationEPSS 0.1%CVE-2026-75587LOWPlaintext pre-auth secret exposure via Desktop App diagnostics reportEPSS 0.1%