Vulnerabilidades en Mattermost

489 resultados
Análisis Vexday

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2024-45835LOWInsufficient Electron Fuses ConfigurationEPSS 0.2%CVE-2026-1629MEDIUMPermalink Preview Information Disclosure After Permission RevocationEPSS 0.2%CVE-2025-53971LOWChannel and Team Membership APIs inadvertently allow loss of Member privileges.EPSS 0.2%CVE-2025-49810LOWThread summarization allows persistent access to channelEPSS 0.2%CVE-2024-40886MEDIUMOne-click Client-Side Path Traversal Leading to CSRF in User Management admin pageEPSS 0.2%CVE-2025-46702MEDIUMMattermost Playbooks allows privilege escalation through improper access control in playbook run participant managementEPSS 0.2%CVE-2026-2299MEDIUMImproper Access Control in Mattermost Google Drive Plugin File Creation EndpointEPSS 0.2%CVE-2026-6334LOWOAuth authorization code client binding not enforced during token redemption in MattermostEPSS 0.2%CVE-2025-13324LOWLack of Invalidation of Legacy Remote Cluster Invite Tokens After ConfirmationEPSS 0.2%CVE-2025-53910MEDIUMUnauthorized Channel Subscription Edit in Mattermost Confluence PluginEPSS 0.2%CVE-2025-8285MEDIUMUnauthorized Channel Subscription Creation in Mattermost Confluence PluginEPSS 0.2%CVE-2025-13523HIGHCross-Site Scripting (XSS) via Unescaped Display Names in Mattermost Confluence Plugin OAuth2 FlowEPSS 0.2%CVE-2025-11776MEDIUMGuest user can discover archived public channelsEPSS 0.2%CVE-2025-13767MEDIUMUnauthorized Read Access to Private Channel Posts via Mattermost Jira PluginEPSS 0.2%CVE-2025-47700LOWAI plugin APIs can be triggered using post actionsEPSS 0.2%CVE-2024-36287LOWBypass of TCC restrictions on macOSEPSS 0.2%CVE-2025-47871MEDIUMMattermost Playbooks exposes private channel metadata to unauthorized users via run metadata APIEPSS 0.2%CVE-2023-5920LOWLack Of Secure Keyboard Entry Protection in MacOS DesktopEPSS 0.2%CVE-2025-6227LOWInvite token is used as part of the secure communicationEPSS 0.2%CVE-2026-21386MEDIUMPrivate channel enumeration via /mute slash commandEPSS 0.2%