Vulnerabilidades en Mattermost

489 resultados
Análisis Vexday

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2023-5160MEDIUMFull name disclosure via team top membership with Show Full Name option disabledEPSS 0.4%CVE-2023-47858MEDIUMDetails of archived public channels are leaked to members of another teamEPSS 0.4%CVE-2026-95666MEDIUMUnbounded post ID array in the bulk reactions endpoint allows denial of serviceEPSS 0.4%CVE-2023-3582MEDIUMLack of channel membership check when linking a board to a channelEPSS 0.4%CVE-2023-2786MEDIUMChannel commands execution doesn't properly verify permissionsEPSS 0.4%CVE-2025-14822LOWDoS from quadratic complexity in model.ParseHashtagsEPSS 0.4%CVE-2026-20719MEDIUMDoS via URL Previews Rendering Malicious SVGsEPSS 0.4%CVE-2023-3614MEDIUMDenial of Service via specially crafted gif imageEPSS 0.4%CVE-2023-3584LOWMember can create team with team override scheme EPSS 0.4%CVE-2024-45833MEDIUMMobile password gets saved in dictionary under conditionsEPSS 0.3%CVE-2023-3615HIGHLack of server certificate validation in websockets connectionEPSS 0.3%CVE-2024-39807LOWChannel IDs of archived/restored channels leaked via webhook eventsEPSS 0.3%CVE-2024-8071MEDIUMSystem Role with edit access to permissions can elevate themselves to system adminEPSS 0.3%CVE-2026-3116MEDIUMImproper Input Validation in Zoom Plugin Webhook HandlerEPSS 0.3%CVE-2026-3114MEDIUMZip Bomb Denial of Service via Unrestricted Archive DecompressionEPSS 0.3%CVE-2025-12419CRITICALAccount takeover on OAuth/OpenID-enabled serversEPSS 0.3%CVE-2025-12421CRITICALAccount Takeover via Code Exchange EndpointEPSS 0.3%CVE-2024-42497MEDIUMInsufficient permissions checks on teamsEPSS 0.3%CVE-2024-39274HIGHMalicious remote can add users to arbitrary teams and channelsEPSS 0.3%CVE-2026-5740HIGHUnauthenticated WebSocket binary frame causes denial of service in Mattermost ServerEPSS 0.3%