Vulnerabilities in Mattermost

489 results
Vexday analysis

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2025-27936MEDIUMWebhook Secret Exposure via Timing attack in MSteams pluginEPSS 0.3%CVE-2024-39839MEDIUMRemote username set to an arbitrary string by remote userEPSS 0.3%CVE-2023-3591MEDIUMLack of previous password reset tokens on new token creationEPSS 0.3%CVE-2025-25068HIGHBypassing MFA Enforcement on Plugin EndpointsEPSS 0.3%CVE-2024-39353LOWRemoteClusterFrame payloads are audit logged in fullEPSS 0.3%CVE-2025-58075HIGHArbitrary Mattermost Team can be joined by manipulating the SAML RelayStateEPSS 0.3%CVE-2025-31947MEDIUMRepeated LDAP login failures can lock an LDAP accountEPSS 0.3%CVE-2025-54525HIGHUnexpected input to Create Channel Subscription endpoint causes DoS in Mattermost Confluence PluginEPSS 0.3%CVE-2023-5194LOWA system/user manager can demote / deactivate another managerEPSS 0.3%CVE-2025-52931HIGHUnexpected input to Update Channel Subscription endpoint causes DoS in Mattermost Confluence PluginEPSS 0.3%CVE-2026-9162MEDIUMGlobal session revocation does not invalidate active WebSocket connectionsEPSS 0.3%CVE-2024-1887MEDIUMPublic channel post content accessible without membership when compliance export is enabledEPSS 0.3%CVE-2024-29221MEDIUMInvite ID available to team admins even without the "Add Members" permissionEPSS 0.3%CVE-2024-1888MEDIUMExisting server guests invited to the team by members without "invite_guest" permissionEPSS 0.3%CVE-2023-5875LOWLack of Hardening against media exploitation from a remote originEPSS 0.3%CVE-2026-2462MEDIUMAdmin RCE via Malicious Plugin Upload on CI Test InstancesEPSS 0.3%CVE-2026-4858HIGHPath traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.EPSS 0.3%CVE-2025-2570LOWSystem Admin Cannot Access Environment settings in System Console While System Manager CanEPSS 0.3%CVE-2025-22445LOWMisleading UI for undefined admin console settings in Calls causes security confusionEPSS 0.3%CVE-2025-10545LOWGuest user can add unauthorized team users to private channelsEPSS 0.3%