Vulnerabilities in Mattermost

489 results
Vexday analysis

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2023-40703MEDIUMDenial of Service via specially crafted block fields in Mattermost BoardsEPSS 0.7%CVE-2023-48268MEDIUMDenial of Service via Board Import Zip BombEPSS 0.7%CVE-2021-37866MEDIUMSession is not invalidated on server-side when user logged out of BoardsEPSS 0.7%CVE-2024-24988MEDIUMExcessive resource consumption when sending long emoji names in user custom statusEPSS 0.7%CVE-2023-2831MEDIUMDenial of Service while unescaping a Markdown stringEPSS 0.7%CVE-2022-1384MEDIUMAuthorized users are allowed to install old plugin versions from the MarketplaceEPSS 0.7%CVE-2021-37867MEDIUMEmails of all users are exposed via one of the Boards APIsEPSS 0.7%CVE-2021-37862LOWMattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into EPSS 0.7%CVE-2022-1002LOWHTML Injection while inviting GuestsEPSS 0.7%CVE-2022-1332MEDIUMRestricted custom admin role can bypass the restrictions and view the server logs and server config.json file contentsEPSS 0.7%CVE-2023-45847MEDIUM Playbook Plugin Crash via Run ChecklistEPSS 0.6%CVE-2023-49607MEDIUMPlaybook plugin crash via missing interface type assertionEPSS 0.6%CVE-2023-6458HIGHClient side path traversal due to lack of route parameters validationEPSS 0.6%CVE-2023-49809MEDIUMTodo plugin gets crashed and disabled by memberEPSS 0.6%CVE-2025-9079HIGHAdmin RCE via prepackaged plugins by way of misconfigured imports directoryEPSS 0.6%CVE-2023-48369MEDIUMLog Flooding due to specially crafted requests in different endpointsEPSS 0.6%CVE-2021-37860LOWMattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary webEPSS 0.6%CVE-2024-54083MEDIUMDoS via lack of type validation in CallsEPSS 0.6%CVE-2023-2792MEDIUMEphemeral messages return private channel contents in permalink previewsEPSS 0.6%CVE-2025-20033MEDIUMDoS via custom post type for sysconsole plugin readersEPSS 0.6%