Exposición de Mattermost
Message boards52
score de exposición
1
sitios usan
0
en explotación
6
críticos
CVEs
421 resultadosCVE-2026-5308MEDIUMMissing request body size limits on Zoom plugin HTTP endpointsEPSS 0.3%CVE-2024-48872MEDIUMBypass of "Max failed attempts" restriction via race conditionEPSS 0.3%CVE-2024-47145LOWUnauthorized access on archived channels via file linksEPSS 0.3%CVE-2025-3228MEDIUMUnauthorized Guest user access to PlaybookEPSS 0.3%CVE-2025-54499LOWInsecure string comparison enables timing attacksEPSS 0.3%CVE-2026-4646MEDIUMInsufficient input validation in GitHub plugin API causes denial of serviceEPSS 0.3%CVE-2025-9081LOWIDOR in board file download allows any user to download any file by UUIDEPSS 0.3%CVE-2025-1412LOWSession Persistence After User-to-Bot ConversionEPSS 0.2%CVE-2026-5755MEDIUMDenial of service via crafted TIFF file uploadEPSS 0.2%CVE-2024-23319LOWCSRF issue allows disconnecting a user's Jira connection through a simple post message (Jira Plugin)EPSS 0.2%CVE-2024-43813MEDIUMIDOR when marking read a user's channelEPSS 0.2%CVE-2024-29215MEDIUMSlash commands run in channel without channel membership via playbook task commandsEPSS 0.2%CVE-2025-0503LOWLeaked User IDs and Metadata of Deleted DMsEPSS 0.2%CVE-2025-9076MEDIUMMattermost Server exposes sensitive user credentials during shared channel membership synchronizationEPSS 0.2%CVE-2024-31859MEDIUMMember promoted to channel admin via playbooks run linking to channelEPSS 0.2%CVE-2026-4054MEDIUMSVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of serviceEPSS 0.2%CVE-2025-2424LOWLeaked Metadata of Deleted Files via Bookmark CreationEPSS 0.2%CVE-2026-8075MEDIUMPosting a malicious markdown image crashes the Mattermost Desktop AppEPSS 0.2%CVE-2026-6850MEDIUMCrafted message attachment causes client-side denial of service via markdown parser regex backtracking in MattermostEPSS 0.2%CVE-2026-10819MEDIUMMattermost Server Denial of Service via Animated GIF Emoji UploadEPSS 0.2%