Exposição de Mattermost

Message boards
44
score de exposição
2
sites usam
0
em exploração
6
críticos

CVEs

454 resultados
CVE-2024-31859MEDIUMMember promoted to channel admin via playbooks run linking to channelEPSS 0.2%CVE-2026-10103MEDIUMAuthenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channelsEPSS 0.2%CVE-2025-1792LOWImproper Access Control in Mattermost Channel Member APIEPSS 0.2%CVE-2026-14298MEDIUMBoards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in MattermostEPSS 0.2%CVE-2026-10819MEDIUMMattermost Server Denial of Service via Animated GIF Emoji UploadEPSS 0.2%CVE-2026-6062MEDIUMIDOR in Jira plugin subscription edit endpointEPSS 0.2%CVE-2026-2325MEDIUMImproper Input Validation in MS Teams Meetings API HandlerEPSS 0.2%CVE-2026-6340MEDIUMMemory Exhaustion via Malicious 7zip File UploadEPSS 0.2%CVE-2025-27538LOWMFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other UsersEPSS 0.2%CVE-2024-32945LOWLaTeX post content manipulation via renderer state leak across contextsEPSS 0.2%CVE-2026-15814MEDIUMUploading a crafted image causes excessive memory allocation in the Mattermost ServerEPSS 0.2%CVE-2026-5132MEDIUMUnbounded zlib decompression in Calls SDP WebSocket messagesEPSS 0.2%CVE-2025-24920MEDIUMUnauthorized Bookmark Creation and Modification in Archived ChannelsEPSS 0.2%CVE-2026-6345MEDIUMPrevent password disclosure and force reset during Slack importEPSS 0.2%CVE-2026-3115MEDIUMGuest users can view group member IDs without respecting view restrictionsEPSS 0.2%CVE-2024-32045MEDIUMPlaybook run link to private channel grants channel accessEPSS 0.2%CVE-2026-9597MEDIUMDeactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpointEPSS 0.2%CVE-2026-3117MEDIUMInstance and webhook GitLab plugin commands were able to be run by non-admin usersEPSS 0.2%CVE-2025-2475MEDIUMUnauthorized Bot Login Using CredentialsEPSS 0.2%CVE-2026-91181MEDIUMData Retention Teams Endpoint Leaks Private Team Invite IDEPSS 0.2%