Exposición de Mattermost

Message boards
44
score de exposición
2
sitios usan
0
en explotación
6
críticos

CVEs

454 resultados
CVE-2026-2462MEDIUMAdmin RCE via Malicious Plugin Upload on CI Test InstancesEPSS 0.3%CVE-2026-4858HIGHPath traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.EPSS 0.3%CVE-2025-2570LOWSystem Admin Cannot Access Environment settings in System Console While System Manager CanEPSS 0.3%CVE-2025-22445LOWMisleading UI for undefined admin console settings in Calls causes security confusionEPSS 0.3%CVE-2025-10545LOWGuest user can add unauthorized team users to private channelsEPSS 0.3%CVE-2025-8402MEDIUMNil pointer dereference in bulk import crashes serverEPSS 0.3%CVE-2023-50333LOWLack of restriction to manage group names for freshly demoted guestsEPSS 0.3%CVE-2023-5331MEDIUMFile Information Leak via IDOR in file_id in Draft PostsEPSS 0.3%CVE-2026-8074LOWImproper Permission Check Allows User Manager to Deactivate Bot AccountsEPSS 0.3%CVE-2026-8823LOWUser Manager can demote bot accounts to guest without bot-management permissionEPSS 0.3%CVE-2023-1774MEDIUMUnauthorized email invite to a private channelEPSS 0.3%CVE-2023-6547LOWPlaybooks access/modification by removed team memberEPSS 0.3%CVE-2025-6226MEDIUMIDOR in CreatePost API allows for timeboxed message disclosureEPSS 0.3%CVE-2025-55035MEDIUMMattermost Desktop DoS when user has basic authentication server configuredEPSS 0.3%CVE-2024-24776LOW Incorrect Authorization leads to Channel Member Count LeakEPSS 0.3%CVE-2024-23488LOWFiles of archived channels accessible with the “Allow users to view archived channels” option disabledEPSS 0.3%CVE-2024-39772LOWSilent Desktop Screenshot CaptureEPSS 0.3%CVE-2023-45316HIGHReflected client side path traversal leading to CSRF in PlaybooksEPSS 0.3%CVE-2025-3913MEDIUMTeam Privacy Settings Authorization Bypass in Mattermost ServerEPSS 0.3%CVE-2026-21388LOWUnbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook EndpointEPSS 0.3%