Exposição de Mattermost

Message boards
44
score de exposição
2
sites usam
0
em exploração
6
críticos

CVEs

454 resultados
CVE-2024-36492HIGHExisting local user overwritten by malicious remoteEPSS 0.3%CVE-2026-10080MEDIUMBoards plugin panics on WebSocket command with non-string field typesEPSS 0.3%CVE-2024-34029MEDIUMAD/LDAP Group Members LeakEPSS 0.3%CVE-2024-52032MEDIUMPrivate channel names leaking when Elasticsearch is enabledEPSS 0.3%CVE-2023-7113LOWMattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web cEPSS 0.3%CVE-2025-58084LOWMattermost Desktop App crashes when clicking on malformed external URLEPSS 0.3%CVE-2024-10241MEDIUMPrivate channel names leaked with Ctrl+K when ElasticSearch is enabledEPSS 0.3%CVE-2025-3228MEDIUMUnauthorized Guest user access to PlaybookEPSS 0.3%CVE-2025-24526MEDIUMChannel export permitted on archived channel when viewing archived channels is disabledEPSS 0.3%CVE-2025-55070MEDIUMLack of MFA enforcement in WebSocket connectionsEPSS 0.3%CVE-2024-42411MEDIUMUser creation date manipulation in POST /api/v4/usersEPSS 0.3%CVE-2026-3109LOWMissing timestamp validation in Zoom webhook handlerEPSS 0.3%CVE-2025-24866LOWUnauthorized Access to User Activity Logs API by delegated granular administration rolesEPSS 0.3%CVE-2026-5139MEDIUMGitLab Plugin Allows Non-Admin Users to Modify Default Instance ConfigurationEPSS 0.3%CVE-2026-10085MEDIUMOrdinary group/direct message member can enable group_constrained and remove all channel participantsEPSS 0.3%CVE-2024-42000LOWUnauthorized Access to view channels' detailsEPSS 0.3%CVE-2025-12689MEDIUMDoS in Calls plugin via malformed UTF-8 in WebSocket requestEPSS 0.3%CVE-2026-25783MEDIUMDenial of service via malformed User-Agent header in getBrowserVersionEPSS 0.3%CVE-2026-7521MEDIUMSAML certificate deletion allows path traversal to delete arbitrary files outside the config directoryEPSS 0.3%CVE-2024-39837LOWMalicious remote can create arbitrary channelsEPSS 0.3%