Exposição de Mattermost

Message boards
52
score de exposição
1
sites usam
0
em exploração
6
críticos

CVEs

421 resultados
CVE-2025-13767MEDIUMUnauthorized Read Access to Private Channel Posts via Mattermost Jira PluginEPSS 0.2%CVE-2026-27769LOWConnected Workspaces: Malicious remote server can manipulate arbitrary user's statusEPSS 0.2%CVE-2025-55074LOWChannel member objects leak read statusEPSS 0.2%CVE-2026-2456MEDIUMDenial of Service via Unbounded Memory Allocation in Integration ActionsEPSS 0.2%CVE-2026-2458MEDIUMUnauthorized channel enumeration in private teams after member removalEPSS 0.2%CVE-2026-6343MEDIUMMattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing unauthorized access to public playbooksEPSS 0.2%CVE-2026-24692MEDIUMGuest users can bypass read permissions via search APIEPSS 0.2%CVE-2026-2455MEDIUMSSRF bypass via IPv4-mapped IPv6 literalsEPSS 0.2%CVE-2026-4053LOWpost edit time limit is not enforced on some post update operationsEPSS 0.2%CVE-2025-41436LOWUnauthorized access to archived channel content via threads interfaceEPSS 0.2%CVE-2025-1398LOWmacOS TCC Bypass via Code InjectionEPSS 0.2%CVE-2026-9824MEDIUMRemote cluster metadata enumeration via /share-channel autocompleteEPSS 0.2%CVE-2025-14350MEDIUMInformation disclosure via channel mentions in postsEPSS 0.2%CVE-2026-2461MEDIUMMissing authorization check allows unauthorized modification of other users' comments on a boardEPSS 0.2%CVE-2025-9072HIGHOne-Click Mattermost Account Takeover via Poisoned RelayState SAML ParameterEPSS 0.2%CVE-2025-9084LOWOpen redirect in OAuth loginEPSS 0.2%CVE-2026-26304MEDIUMPermission Bypass in Playbook Run CreationEPSS 0.2%CVE-2026-26230LOWTeam Admin Privilege Escalation to Demote Members to GuestEPSS 0.2%CVE-2025-14573LOWTeam Admin Bypass of Invite Permissions via allow_open_invite FieldEPSS 0.2%CVE-2024-46872MEDIUMClient-Side Path Traversal Leading to CSRF in PlaybooksEPSS 0.2%