Vulnerabilities in Mattermost

489 results
Vexday analysis

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2023-2514MEDIUMDB username/password revealed in application logsEPSS 0.5%CVE-2023-1775MEDIUMUnsanitized events sent over Websocket to regular users in a High Availability environmentEPSS 0.5%CVE-2023-2787MEDIUMCollapsed Reply Threads APIs leak message contents from private channelsEPSS 0.5%CVE-2023-3585MEDIUMchannel DoS by sharing a boards linkEPSS 0.5%CVE-2024-22091LOWExcessive resource consumption due to lack to request path size limitsEPSS 0.5%CVE-2023-1777MEDIUMInformation disclosure in linked message previewsEPSS 0.5%CVE-2023-6459MEDIUMPublic endpoint /metrics of Calls plugin reveals channel IDsEPSS 0.5%CVE-2023-5969MEDIUM Denial of Service via Link Preview in /api/v4/redirect_locationEPSS 0.5%CVE-2025-20072MEDIUMMobile crash via improper validation of proto style in attachmentsEPSS 0.5%CVE-2023-27265LOWDisclosure of team owner email address when regenerating Invite IDEPSS 0.5%CVE-2023-27266LOWDisclosure of team owner email address when when accessing the teams APIEPSS 0.5%CVE-2024-1402MEDIUMDenial of service in mattermost mobile apps and server via emoji reactionsEPSS 0.5%CVE-2025-21083MEDIUMInsufficient Input Validation on Post PropsEPSS 0.5%CVE-2025-20036MEDIUMInsufficient Input Validation on Post PropsEPSS 0.5%CVE-2023-5968MEDIUMPassword hash in response body after username updateEPSS 0.5%CVE-2023-4107MEDIUMIncorrect authorization allows a user manager to update a system adminEPSS 0.5%CVE-2024-1953MEDIUMMattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested fEPSS 0.5%CVE-2023-5967MEDIUMDenial of Service via crashing the Calls PluginEPSS 0.5%CVE-2024-28053LOWResource Exhaustion via the Invitation FeatureEPSS 0.5%CVE-2023-45223MEDIUMUsers full name disclosure through Mattermost Boards with Show Full Name Option disabledEPSS 0.5%