Vulnerabilities in Mattermost

489 results
Vexday analysis

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2025-6233MEDIUMArbitrary file read by system admin via path traversalEPSS 0.4%CVE-2025-25274MEDIUMUnauthorized Command Execution in Archived ChannelsEPSS 0.4%CVE-2024-39830HIGHTiming attack during remote cluster token comparison when shared channels are enabledEPSS 0.4%CVE-2026-3524HIGHAuthorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission CheckEPSS 0.4%CVE-2023-3577LOWLimited blind SSRF to localhost/intranet in interactive dialog implementationEPSS 0.4%CVE-2023-5522MEDIUMMobile app freezes when receiving a post with hundreds of emojisEPSS 0.4%CVE-2023-49874MEDIUMIDOR when updating the tasks of a private playbook runEPSS 0.4%CVE-2025-1558MEDIUMDenial of Service Via Malicious GIFEPSS 0.4%CVE-2023-35075LOWHTML injection via channel autocompleteEPSS 0.4%CVE-2024-1952LOWMattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing anEPSS 0.4%CVE-2023-5159LOWA User Manager role with user edit permissions could manage/update botsEPSS 0.4%CVE-2025-0476MEDIUMMobile crash via file with specially crafted filenameEPSS 0.4%CVE-2023-4106MEDIUMA guest user can perform various actions on public playbooksEPSS 0.4%CVE-2023-2000MEDIUMUnrestricted navigation due to unvalidated mattermost server redirectionEPSS 0.4%CVE-2024-39777HIGHMalicious remote can invite itself to an arbitrary local channelEPSS 0.4%CVE-2024-41144MEDIUMMalicious remote can create/update/delete arbitrary posts in arbitrary channelsEPSS 0.4%CVE-2026-9708MEDIUMIncoming webhook user attribution via unvalidated webhook ownerEPSS 0.4%CVE-2024-10214LOWIncorrect Session Creation with Desktop SSOEPSS 0.4%CVE-2024-1942MEDIUMMattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under speEPSS 0.4%CVE-2023-5160MEDIUMFull name disclosure via team top membership with Show Full Name option disabledEPSS 0.4%