Exposição de Mattermost
Message boards52
score de exposição
1
sites usam
0
em exploração
6
críticos
CVEs
421 resultadosCVE-2025-10545LOWGuest user can add unauthorized team users to private channelsEPSS 0.3%CVE-2026-6346HIGHSensitive credentials exposed in plaintext in Mattermost support packetsEPSS 0.3%CVE-2025-49222MEDIUMMattermost Shared Channel Upload Type Validation BypassEPSS 0.3%CVE-2024-37182MEDIUMLack of permissions prompting when opening external URLsEPSS 0.3%CVE-2026-6673MEDIUMMattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud installEPSS 0.3%CVE-2024-39613MEDIUMRCE in desktop app in Windows by local attackerEPSS 0.3%CVE-2025-55070MEDIUMLack of MFA enforcement in WebSocket connectionsEPSS 0.3%CVE-2026-6957HIGHPath traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file write.EPSS 0.3%CVE-2024-36492HIGHExisting local user overwritten by malicious remoteEPSS 0.3%CVE-2025-55035MEDIUMMattermost Desktop DoS when user has basic authentication server configuredEPSS 0.3%CVE-2024-34029MEDIUMAD/LDAP Group Members LeakEPSS 0.3%CVE-2023-7113LOWMattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web cEPSS 0.3%CVE-2024-10241MEDIUMPrivate channel names leaked with Ctrl+K when ElasticSearch is enabledEPSS 0.3%CVE-2024-42411MEDIUMUser creation date manipulation in POST /api/v4/usersEPSS 0.3%CVE-2025-30179MEDIUMMFA Enforcement Bypass in Search APIsEPSS 0.3%CVE-2026-3109LOWMissing timestamp validation in Zoom webhook handlerEPSS 0.3%CVE-2024-52032MEDIUMPrivate channel names leaking when Elasticsearch is enabledEPSS 0.3%CVE-2026-5139MEDIUMGitLab Plugin Allows Non-Admin Users to Modify Default Instance ConfigurationEPSS 0.3%CVE-2026-25783MEDIUMDenial of service via malformed User-Agent header in getBrowserVersionEPSS 0.3%CVE-2026-7521MEDIUMSAML certificate deletion allows path traversal to delete arbitrary files outside the config directoryEPSS 0.3%