Vulnerabilidades en Mattermost

438 resultados
Análisis Vexday

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2025-47870MEDIUMTeam invite ID leaked to team admin with no member invite privilegesEPSS 0.2%CVE-2025-27715LOWAuto-Enrollment of Team Admins into Private Channels without explicit consentEPSS 0.2%CVE-2026-20796LOWTime-of-check time-of-use vulnerability in common teams APIEPSS 0.2%CVE-2026-8683MEDIUMOverly long URLs crash the Mattermost Desktop AppEPSS 0.2%CVE-2025-3446MEDIUMMembers Without Guest Invite Permissions Can Add Guests to TeamsEPSS 0.2%CVE-2025-13821MEDIUMUser profile update exposes password hash and MFA secretsEPSS 0.2%CVE-2025-32093MEDIUMSyatem admin profile modification by delegated granular administration roleEPSS 0.2%CVE-2025-27538LOWMFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other UsersEPSS 0.2%CVE-2025-27933MEDIUMUnauthorized Private-to-Public Channel ConversionEPSS 0.2%CVE-2025-44001MEDIUMUnauthorized Channel Subscription Read in Mattermost Confluence PluginEPSS 0.2%CVE-2025-54458MEDIUMUnauthorized Subscription Creation to Confluence Space in Mattermost Confluence PluginEPSS 0.2%CVE-2025-53857LOWLack of Authorization on Get Channel Subscriptions for Autocomplete in Mattermost Confluence PluginEPSS 0.2%CVE-2026-8074LOWImproper Permission Check Allows User Manager to Deactivate Bot AccountsEPSS 0.2%CVE-2025-3611LOWImproper Access Control in Mattermost allows System Managers to view team details despite role restrictionsEPSS 0.2%CVE-2024-36287LOWBypass of TCC restrictions on macOSEPSS 0.2%CVE-2026-6046MEDIUMPlugin bot username conflict allows user account to be used as bot identity in Mattermost ServerEPSS 0.2%CVE-2024-40886MEDIUMOne-click Client-Side Path Traversal Leading to CSRF in User Management admin pageEPSS 0.2%CVE-2025-44004HIGHUnauthenticated Channel Subscription Creation in Mattermost Confluence PluginEPSS 0.2%CVE-2025-53971LOWChannel and Team Membership APIs inadvertently allow loss of Member privileges.EPSS 0.2%CVE-2025-13523HIGHCross-Site Scripting (XSS) via Unescaped Display Names in Mattermost Confluence Plugin OAuth2 FlowEPSS 0.2%