Exposure of Mattermost

Message boards
52
exposure score
1
sites use
0
exploited
6
critical

CVEs

421 results
CVE-2023-2791MEDIUMPlaybooks lets you edit arbitrary postsEPSS 0.4%CVE-2024-6428MEDIUMLimited DoS due to permitting creating users with user-defined IDsEPSS 0.4%CVE-2024-40884LOWUnauthorized disabling of invite URLEPSS 0.4%CVE-2024-23493MEDIUM Team associated AD/LDAP Groups Leaked due to missing authorizationEPSS 0.4%CVE-2025-58073HIGHArbitrary Mattermost Team can be joined by manipulating the OAuth stateEPSS 0.4%CVE-2025-6233MEDIUMArbitrary file read by system admin via path traversalEPSS 0.4%CVE-2024-39830HIGHTiming attack during remote cluster token comparison when shared channels are enabledEPSS 0.4%CVE-2026-3524HIGHAuthorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission CheckEPSS 0.4%CVE-2023-3577LOWLimited blind SSRF to localhost/intranet in interactive dialog implementationEPSS 0.4%CVE-2023-5522MEDIUMMobile app freezes when receiving a post with hundreds of emojisEPSS 0.4%CVE-2023-49874MEDIUMIDOR when updating the tasks of a private playbook runEPSS 0.4%CVE-2025-35965MEDIUMDoS in Mattermost Playbooks via Excessive Task ActionsEPSS 0.4%CVE-2023-35075LOWHTML injection via channel autocompleteEPSS 0.4%CVE-2024-1952LOWMattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing anEPSS 0.4%CVE-2023-5159LOWA User Manager role with user edit permissions could manage/update botsEPSS 0.4%CVE-2024-39777HIGHMalicious remote can invite itself to an arbitrary local channelEPSS 0.4%CVE-2023-2000MEDIUMUnrestricted navigation due to unvalidated mattermost server redirectionEPSS 0.4%CVE-2024-41144MEDIUMMalicious remote can create/update/delete arbitrary posts in arbitrary channelsEPSS 0.4%CVE-2024-10214LOWIncorrect Session Creation with Desktop SSOEPSS 0.4%CVE-2024-1942MEDIUMMattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under speEPSS 0.4%