Exposição de Mattermost

Message boards
52
score de exposição
1
sites usam
0
em exploração
6
críticos

CVEs

421 resultados
CVE-2024-5270MEDIUMSAML to email switch possible when email signin is disabledEPSS 0.3%CVE-2026-24458HIGHDoS attack via login attempts with multi-megabyte passwordsEPSS 0.3%CVE-2025-11794MEDIUMPassword hash and MFA secret returned in user email verification endpointEPSS 0.3%CVE-2025-2564MEDIUMUnauthorized View Access to Archived Channel Member InfoEPSS 0.3%CVE-2026-25780MEDIUMMemory Exhaustion via Malformed DOC File UploadEPSS 0.3%CVE-2026-6347HIGHMattermost Calls plugin exposes TURN server credentials in plaintext in support packetsEPSS 0.3%CVE-2024-1949LOWA race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized accEPSS 0.3%CVE-2025-3913MEDIUMTeam Privacy Settings Authorization Bypass in Mattermost ServerEPSS 0.3%CVE-2025-31363LOWData exfiltration via AI plugin Jira toolEPSS 0.3%CVE-2025-30516LOWUnauthorized Notification Exposure in Mobile App Under Specific ConditionsEPSS 0.3%CVE-2023-3581MEDIUMWebSockets accept connections from HTTPS originEPSS 0.3%CVE-2025-41423LOWUnauthorized Playbooks Post Deletion in Mattermost Playbooks PluginEPSS 0.3%CVE-2024-39836MEDIUMMunged email address used for password resets and notificationsEPSS 0.3%CVE-2024-9155MEDIUMInsufficient Authorization On Unlinked Channel FilesEPSS 0.3%CVE-2024-34152MEDIUMPlaybook Run Metadata leak to GuestEPSS 0.3%CVE-2024-36241LOW/playbook add slash command allows viewing arbitrary post contentsEPSS 0.3%CVE-2026-6739MEDIUMMattermost: Delegated admins could patch protected default system rolesEPSS 0.3%CVE-2025-27571MEDIUMChannel metadata visible in archived channels despite configuration settingEPSS 0.3%CVE-2025-12689MEDIUMDoS in Calls plugin via malformed UTF-8 in WebSocket requestEPSS 0.3%CVE-2026-7184MEDIUMMattermost Remote Cluster PATCH API Leaks Authentication TokensEPSS 0.3%