Exposição de Mattermost
Message boards44
score de exposição
2
sites usam
0
em exploração
6
críticos
CVEs
454 resultadosCVE-2026-9820LOWMattermost schemes teams endpoint exposes private team invite IDsEPSS 0.3%CVE-2026-5308MEDIUMMissing request body size limits on Zoom plugin HTTP endpointsEPSS 0.3%CVE-2026-6541MEDIUMUnscoped updates to other playbooks' metric configurationEPSS 0.3%CVE-2025-0503LOWLeaked User IDs and Metadata of Deleted DMsEPSS 0.3%CVE-2026-9859MEDIUMMattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose boards to arbitrary channelsEPSS 0.3%CVE-2025-2424LOWLeaked Metadata of Deleted Files via Bookmark CreationEPSS 0.3%CVE-2024-47145LOWUnauthorized access on archived channels via file linksEPSS 0.3%CVE-2026-4646MEDIUMInsufficient input validation in GitHub plugin API causes denial of serviceEPSS 0.3%CVE-2026-10556MEDIUMUnauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.EPSS 0.2%CVE-2026-22892MEDIUMInsufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post AttachmentsEPSS 0.2%CVE-2025-1472MEDIUMUnauthorized View Access to Site Statistics and Team StatisticsEPSS 0.2%CVE-2025-3227MEDIUMUnauthorized channel member management through playbook runsEPSS 0.2%CVE-2026-5755MEDIUMDenial of service via crafted TIFF file uploadEPSS 0.2%CVE-2024-23319LOWCSRF issue allows disconnecting a user's Jira connection through a simple post message (Jira Plugin)EPSS 0.2%CVE-2026-1046HIGHArbitrary application execution via unvalidated server-controlled URLs in Help menuEPSS 0.2%CVE-2024-43813MEDIUMIDOR when marking read a user's channelEPSS 0.2%CVE-2025-3446MEDIUMMembers Without Guest Invite Permissions Can Add Guests to TeamsEPSS 0.2%CVE-2024-29215MEDIUMSlash commands run in channel without channel membership via playbook task commandsEPSS 0.2%CVE-2025-32093MEDIUMSyatem admin profile modification by delegated granular administration roleEPSS 0.2%CVE-2026-4054MEDIUMSVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of serviceEPSS 0.2%