Exposición de Mattermost
Message boards52
score de exposición
1
sitios usan
0
en explotación
6
críticos
CVEs
421 resultadosCVE-2026-0998MEDIUMMattermost Zoom Plugin allows unauthorized meeting creation and post modification via insufficient API access controlsEPSS 0.2%CVE-2026-4055MEDIUMInsufficient permission validation on cross-team playbook run creationEPSS 0.2%CVE-2026-28759MEDIUMInsufficient authorization in shared channel membership sync allows remote cluster to remove users from arbitrary channelsEPSS 0.2%CVE-2026-6689MEDIUM*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings*EPSS 0.2%CVE-2026-0997MEDIUMMattermost Zoom Plugin channel preference API lacks authorization checksEPSS 0.2%CVE-2026-28732MEDIUMSlash command trigger-word update allowed command hijackingEPSS 0.2%CVE-2026-6541MEDIUMUnscoped updates to other playbooks' metric configurationEPSS 0.2%CVE-2026-6342MEDIUMGroup prefix matching bypass for subscriptionsEPSS 0.2%CVE-2026-3637MEDIUMMattermost fails to enforce create_post permission when editing postsEPSS 0.2%CVE-2026-6341MEDIUMIncomplete group locking implementationEPSS 0.2%CVE-2026-9820LOWMattermost schemes teams endpoint exposes private team invite IDsEPSS 0.2%CVE-2025-13352LOWMattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijackingEPSS 0.2%CVE-2026-3473MEDIUMImproper file ownership validation in the Boards API allows unauthorised file accessEPSS 0.1%CVE-2025-64641MEDIUMMattermost Jira plugin crafted action leaks Jira issue detailsEPSS 0.1%CVE-2026-22545LOWPassword Change Bypass via Auth Switch EndpointEPSS 0.1%CVE-2026-3590MEDIUMRace Condition in Guest Magic Link Authentication Allows Token ReuseEPSS 0.1%CVE-2026-10103MEDIUMAuthenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channelsEPSS 0.1%CVE-2023-5339MEDIUMMattermost Desktop logs all keystrokes during initial run after fresh installation EPSS 0.1%CVE-2026-3495LOWUnescaped variables during error page compositionEPSS 0.1%CVE-2026-4286LOWPlaybooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook updateEPSS 0.1%