Exposición de Mattermost

Message boards
52
score de exposición
1
sitios usan
0
en explotación
6
críticos

CVEs

421 resultados
CVE-2024-40886MEDIUMOne-click Client-Side Path Traversal Leading to CSRF in User Management admin pageEPSS 0.2%CVE-2025-27715LOWAuto-Enrollment of Team Admins into Private Channels without explicit consentEPSS 0.2%CVE-2026-8683MEDIUMOverly long URLs crash the Mattermost Desktop AppEPSS 0.2%CVE-2025-49810LOWThread summarization allows persistent access to channelEPSS 0.2%CVE-2026-20796LOWTime-of-check time-of-use vulnerability in common teams APIEPSS 0.2%CVE-2025-13821MEDIUMUser profile update exposes password hash and MFA secretsEPSS 0.2%CVE-2025-27933MEDIUMUnauthorized Private-to-Public Channel ConversionEPSS 0.2%CVE-2026-3472LOWMarkdown image rendering bypass in AI bot tool result posts in MattermostEPSS 0.2%CVE-2025-3611LOWImproper Access Control in Mattermost allows System Managers to view team details despite role restrictionsEPSS 0.2%CVE-2026-6046MEDIUMPlugin bot username conflict allows user account to be used as bot identity in Mattermost ServerEPSS 0.2%CVE-2024-36287LOWBypass of TCC restrictions on macOSEPSS 0.2%CVE-2025-11776MEDIUMGuest user can discover archived public channelsEPSS 0.2%CVE-2026-6517MEDIUMMattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passedEPSS 0.2%CVE-2025-3230MEDIUMBypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost ServerEPSS 0.2%CVE-2025-47700LOWAI plugin APIs can be triggered using post actionsEPSS 0.2%CVE-2025-4128LOWMattermost Guest User Information Disclosure VulnerabilityEPSS 0.2%CVE-2026-3471MEDIUMOpening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop AppEPSS 0.2%CVE-2026-3636MEDIUMSanitize team member data returned by APIEPSS 0.2%CVE-2026-21386MEDIUMPrivate channel enumeration via /mute slash commandEPSS 0.2%CVE-2024-36255MEDIUMPost actions can run playbook checklist task commandsEPSS 0.2%