Exposição de Mattermost
Message boards44
score de exposição
2
sites usam
0
em exploração
6
críticos
CVEs
454 resultadosCVE-2025-31363LOWData exfiltration via AI plugin Jira toolEPSS 0.3%CVE-2024-5272MEDIUMRun Details leak to guest via webhook event "custom_playbooks_playbook_run_updated"EPSS 0.3%CVE-2026-12985MEDIUMMattermost DCR redirect URI allowlist bypass via improper URL component validationEPSS 0.3%CVE-2025-2564MEDIUMUnauthorized View Access to Archived Channel Member InfoEPSS 0.3%CVE-2026-3108HIGHTerminal Escape Injection in mmctl Report Posts CommandEPSS 0.3%CVE-2025-11794MEDIUMPassword hash and MFA secret returned in user email verification endpointEPSS 0.3%CVE-2023-3586MEDIUM Disabling publicly-shared boards does not disable existing publicly available board linksEPSS 0.3%CVE-2024-43780MEDIUMUnauthorized channel file uploadEPSS 0.3%CVE-2024-50052MEDIUMArbitrary post deletion via Playbooks /ignore-thread endpointEPSS 0.3%CVE-2025-22449LOWAccess control flaw for team admins allows unauthorized team additionsEPSS 0.3%CVE-2026-4915MEDIUMServer panic via outgoing webhook responsesEPSS 0.3%CVE-2024-39361LOWCreating posts with user-defined IDs permitted in CreatePost APIEPSS 0.3%CVE-2025-4573MEDIUMLDAP Injection in Mattermost Enterprise Edition When Using Active DirectoryEPSS 0.3%CVE-2024-41162MEDIUMMalicious remote can make an arbitrary local channel read-onlyEPSS 0.3%CVE-2024-29977LOWMalicious remote can create arbitrary reactions on arbitrary postsEPSS 0.3%CVE-2025-30516LOWUnauthorized Notification Exposure in Mobile App Under Specific ConditionsEPSS 0.3%CVE-2026-2454MEDIUMDoS in Calls plugin via malformed msgpack in websocket request.EPSS 0.3%CVE-2024-5270MEDIUMSAML to email switch possible when email signin is disabledEPSS 0.3%CVE-2026-24458HIGHDoS attack via login attempts with multi-megabyte passwordsEPSS 0.3%CVE-2025-41423LOWUnauthorized Playbooks Post Deletion in Mattermost Playbooks PluginEPSS 0.3%