Exposición de Mattermost
Message boards44
score de exposición
2
sitios usan
0
en explotación
6
críticos
CVEs
454 resultadosCVE-2026-3116MEDIUMImproper Input Validation in Zoom Plugin Webhook HandlerEPSS 0.3%CVE-2024-8071MEDIUMSystem Role with edit access to permissions can elevate themselves to system adminEPSS 0.3%CVE-2026-3114MEDIUMZip Bomb Denial of Service via Unrestricted Archive DecompressionEPSS 0.3%CVE-2025-12419CRITICALAccount takeover on OAuth/OpenID-enabled serversEPSS 0.3%CVE-2025-12421CRITICALAccount Takeover via Code Exchange EndpointEPSS 0.3%CVE-2024-42497MEDIUMInsufficient permissions checks on teamsEPSS 0.3%CVE-2024-39274HIGHMalicious remote can add users to arbitrary teams and channelsEPSS 0.3%CVE-2026-5740HIGHUnauthenticated WebSocket binary frame causes denial of service in Mattermost ServerEPSS 0.3%CVE-2025-27936MEDIUMWebhook Secret Exposure via Timing attack in MSteams pluginEPSS 0.3%CVE-2023-3591MEDIUMLack of previous password reset tokens on new token creationEPSS 0.3%CVE-2024-39839MEDIUMRemote username set to an arbitrary string by remote userEPSS 0.3%CVE-2025-25068HIGHBypassing MFA Enforcement on Plugin EndpointsEPSS 0.3%CVE-2024-39353LOWRemoteClusterFrame payloads are audit logged in fullEPSS 0.3%CVE-2025-58075HIGHArbitrary Mattermost Team can be joined by manipulating the SAML RelayStateEPSS 0.3%CVE-2025-31947MEDIUMRepeated LDAP login failures can lock an LDAP accountEPSS 0.3%CVE-2023-5194LOWA system/user manager can demote / deactivate another managerEPSS 0.3%CVE-2026-9162MEDIUMGlobal session revocation does not invalidate active WebSocket connectionsEPSS 0.3%CVE-2024-29221MEDIUMInvite ID available to team admins even without the "Add Members" permissionEPSS 0.3%CVE-2024-1888MEDIUMExisting server guests invited to the team by members without "invite_guest" permissionEPSS 0.3%CVE-2024-1887MEDIUMPublic channel post content accessible without membership when compliance export is enabledEPSS 0.3%