Vulnerabilities in Mattermost

489 results
Vexday analysis

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2023-43754MEDIUMPermalink previews displayed for posts in archived channels even if users are disallowed to view archived channelsEPSS 0.5%CVE-2023-2788MEDIUMDeactivated user can retain access using oauth2 apiEPSS 0.5%CVE-2023-4478MEDIUMParameter tampering in the registration resulting in blocked accounts to be createdEPSS 0.5%CVE-2022-1003LOWSysadmin can override existing configs & bypass restrictions like EnableUploadsEPSS 0.5%CVE-2024-4195LOWMattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authentEPSS 0.5%CVE-2023-27264HIGHIDOR: Updating a playbook via the Playbooks APIEPSS 0.5%CVE-2024-4198LOWMattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authentiEPSS 0.5%CVE-2023-27263MEDIUMIDOR: Accessing playbook runs via the Playbooks Runs APIEPSS 0.5%CVE-2023-5330MEDIUM Denial of Service via Opengraph Data CacheEPSS 0.5%CVE-2023-5876LOWRegex DoS from a malicious server enrolled in DesktopEPSS 0.5%CVE-2025-36530MEDIUMImport Path Traversal Enables Unauthorized Unsigned Plugin InstallationEPSS 0.5%CVE-2023-5333MEDIUM Denial of Service via multiple identical User IDs in /api/v4/users/idsEPSS 0.5%CVE-2025-41395MEDIUMWebapp DoS via malicious retrospective post in PlaybooksEPSS 0.5%CVE-2023-2281LOWArchiving a team broadcasts unsanitized data over WebSocketsEPSS 0.5%CVE-2023-5193MEDIUMSystem Role with manage posts permission can read posts of Direct MessagesEPSS 0.5%CVE-2023-2515MEDIUMPrivilege escalation to system admin via personal access tokensEPSS 0.5%CVE-2024-11599HIGHDomain Restriction Bypass on RegistrationEPSS 0.5%CVE-2023-2797LOWPath traversal in GitHub plugin's code preview featureEPSS 0.5%CVE-2024-3872LOWMattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which alloEPSS 0.5%CVE-2023-1562LOWFull name revealed via /plugins/focalboard/api/v2/usersEPSS 0.5%