Exposición de Mattermost

Message boards
52
score de exposición
1
sitios usan
0
en explotación
6
críticos

CVEs

421 resultados
CVE-2025-46702MEDIUMMattermost Playbooks allows privilege escalation through improper access control in playbook run participant managementEPSS 0.2%CVE-2026-2476HIGHMS Teams plugin sensitive config values not properly masked in support packetsEPSS 0.2%CVE-2026-27656MEDIUMAccount Takeover via Substring Matching in OpenID Connect AuthenticationEPSS 0.2%CVE-2026-3433MEDIUMMattermost fails to scope role_updated websocket events to authorized team and channel membersEPSS 0.2%CVE-2025-55073MEDIUMMS Teams plugin OAuth allows editing arbitrary postsEPSS 0.2%CVE-2025-12756MEDIUMInsecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment DeletionEPSS 0.2%CVE-2025-13324LOWLack of Invalidation of Legacy Remote Cluster Invite Tokens After ConfirmationEPSS 0.2%CVE-2025-11777LOWCross-team channel membership accessEPSS 0.2%CVE-2026-10106MEDIUMUnauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in MattermostEPSS 0.2%CVE-2025-2571MEDIUMGoogle OAuth Authentication Bypass for Converted Bot AccountsEPSS 0.2%CVE-2024-41926LOWMalicious remote can claim that a user was synced from another remoteEPSS 0.2%CVE-2025-6227LOWInvite token is used as part of the secure communicationEPSS 0.2%CVE-2026-9571MEDIUMDeactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in MattermostEPSS 0.2%CVE-2026-4635MEDIUMPersistent notification timing attack causing server denial of serviceEPSS 0.2%CVE-2026-0999MEDIUMAuthentication bypass via userID login when email and username login are disabledEPSS 0.2%CVE-2025-47871MEDIUMMattermost Playbooks exposes private channel metadata to unauthorized users via run metadata APIEPSS 0.2%CVE-2026-4643LOWCalling window.close() from server-side content causes crash in the Mattermost Desktop AppEPSS 0.2%CVE-2026-10085MEDIUMOrdinary group/direct message member can enable group_constrained and remove all channel participantsEPSS 0.2%CVE-2026-2463MEDIUMUnauthorized access to invite ID during team creationEPSS 0.2%CVE-2024-12247MEDIUMImproper propagation of permission scheme updates across cluster nodesEPSS 0.2%