Vulnerabilidades en Mattermost

489 resultados
Análisis Vexday

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2023-7113LOWMattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web cEPSS 0.3%CVE-2024-36492HIGHExisting local user overwritten by malicious remoteEPSS 0.3%CVE-2025-58084LOWMattermost Desktop App crashes when clicking on malformed external URLEPSS 0.3%CVE-2024-10241MEDIUMPrivate channel names leaked with Ctrl+K when ElasticSearch is enabledEPSS 0.3%CVE-2023-3613LOWGuest accounts invited and added to channels by Welcomebot pluginEPSS 0.3%CVE-2025-3228MEDIUMUnauthorized Guest user access to PlaybookEPSS 0.3%CVE-2025-24526MEDIUMChannel export permitted on archived channel when viewing archived channels is disabledEPSS 0.3%CVE-2026-16049LOW_GitLab Plugin allows cross-channel post injection and phishing via missing channel permission checks in issue API endpoints_EPSS 0.3%CVE-2024-42411MEDIUMUser creation date manipulation in POST /api/v4/usersEPSS 0.3%CVE-2026-13426MEDIUMClient4 fails to validate path parametersEPSS 0.3%CVE-2025-24866LOWUnauthorized Access to User Activity Logs API by delegated granular administration rolesEPSS 0.3%CVE-2026-8821HIGHPlaybooks run owner channel membership permission bypassEPSS 0.3%CVE-2025-12689MEDIUMDoS in Calls plugin via malformed UTF-8 in WebSocket requestEPSS 0.3%CVE-2026-4643LOWCalling window.close() from server-side content causes crash in the Mattermost Desktop AppEPSS 0.3%CVE-2024-42000LOWUnauthorized Access to view channels' detailsEPSS 0.3%CVE-2026-5139MEDIUMGitLab Plugin Allows Non-Admin Users to Modify Default Instance ConfigurationEPSS 0.3%CVE-2026-10085MEDIUMOrdinary group/direct message member can enable group_constrained and remove all channel participantsEPSS 0.3%CVE-2026-16044LOWInsufficient validation of guest board admin privileges on archive importEPSS 0.3%CVE-2026-4635MEDIUMPersistent notification timing attack causing server denial of serviceEPSS 0.3%CVE-2025-53514MEDIUMUnexpected Input to Server Webhook endpoint Causes DoS in Mattermost Confluence PluginEPSS 0.3%