Vulnerabilities in Mattermost

489 results
Vexday analysis

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2023-7114HIGHMattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.EPSS 0.5%CVE-2024-39832MEDIUMPermanently local data deletion by malicious remoteEPSS 0.5%CVE-2024-47401MEDIUMDoS via Amplified GraphQL Response in PlaybooksEPSS 0.5%CVE-2023-48732MEDIUMKeywords that trigger mentions are leaked to other usersEPSS 0.5%CVE-2025-20621MEDIUMWebapp crash via object that can't be cast to String in Attachment FieldEPSS 0.5%CVE-2026-9699MEDIUMMattermost Agents plugin logs unsanitized OpenAI API keys on authentication errorsEPSS 0.5%CVE-2024-24774LOWMissing authorization allows users to access arbitrary security levels on Jira through webhooks (Jira Plugin)EPSS 0.5%CVE-2024-39810MEDIUMServer crash via Elasticsearch certificate fileEPSS 0.5%CVE-2024-32046MEDIUMDetailed error discloses full file path with dev mode offEPSS 0.5%CVE-2023-1776HIGHStored XSS via SVG attachment on BoardsEPSS 0.4%CVE-2024-2446MEDIUMMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentioEPSS 0.4%CVE-2023-6202MEDIUMInsecure Direct Object Reference in /plugins/focalboard/ api/v2/users of Mattermost BoardsEPSS 0.4%CVE-2024-54682MEDIUMZipbomb DoS via Missing Slack Import ValidationEPSS 0.4%CVE-2023-2783MEDIUMApp Framework does not checks for the secret provided in the incoming webhook requestEPSS 0.4%CVE-2025-24490CRITICALSQL Injection in Mattermost Boards via board category ID reorderingEPSS 0.4%CVE-2023-46701MEDIUMInaccessible Post Information Leak via Run Timeline IDOREPSS 0.4%CVE-2023-3587LOWInconsistent state in UI after boards permission change by system adminEPSS 0.4%CVE-2024-43105MEDIUMExcessive Resource Consumption via `/export`EPSS 0.4%CVE-2023-3590LOWDeleted attachments in Boards remain accessibleEPSS 0.4%CVE-2025-20086MEDIUMInsufficient Input Validation on Post PropsEPSS 0.4%