Exposición de Mattermost
Message boards44
score de exposición
2
sitios usan
0
en explotación
6
críticos
CVEs
454 resultadosCVE-2023-1421LOWReflected XSS in OAuth flow completion endpointsEPSS 0.4%CVE-2023-6727LOWLeak Inaccessible Playbook Information via Channel Action IDOREPSS 0.4%CVE-2023-2808MEDIUMLack of URL normalization allows rendering previews for disallowed domainsEPSS 0.4%CVE-2025-8023MEDIUMPath Traversal in Template Upload Allows Uploading Files Outside Target DirectoryEPSS 0.4%CVE-2023-47168MEDIUMOpen redirect in /oauth/<service>/mobile_login?redirect_to=EPSS 0.4%CVE-2023-2791MEDIUMPlaybooks lets you edit arbitrary postsEPSS 0.4%CVE-2023-4105LOWAttachment of deleted message in a thread remains accessible and downloadable EPSS 0.4%CVE-2025-35965MEDIUMDoS in Mattermost Playbooks via Excessive Task ActionsEPSS 0.4%CVE-2024-6428MEDIUMLimited DoS due to permitting creating users with user-defined IDsEPSS 0.4%CVE-2024-40884LOWUnauthorized disabling of invite URLEPSS 0.4%CVE-2024-23493MEDIUM Team associated AD/LDAP Groups Leaked due to missing authorizationEPSS 0.4%CVE-2025-6233MEDIUMArbitrary file read by system admin via path traversalEPSS 0.4%CVE-2024-39830HIGHTiming attack during remote cluster token comparison when shared channels are enabledEPSS 0.4%CVE-2025-25274MEDIUMUnauthorized Command Execution in Archived ChannelsEPSS 0.4%CVE-2026-3524HIGHAuthorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission CheckEPSS 0.4%CVE-2023-3577LOWLimited blind SSRF to localhost/intranet in interactive dialog implementationEPSS 0.4%CVE-2023-5522MEDIUMMobile app freezes when receiving a post with hundreds of emojisEPSS 0.4%CVE-2023-49874MEDIUMIDOR when updating the tasks of a private playbook runEPSS 0.4%CVE-2025-1558MEDIUMDenial of Service Via Malicious GIFEPSS 0.4%CVE-2023-35075LOWHTML injection via channel autocompleteEPSS 0.4%