Exposição de Mattermost

Message boards
44
score de exposição
2
sites usam
0
em exploração
6
críticos

CVEs

454 resultados
CVE-2024-12247MEDIUMImproper propagation of permission scheme updates across cluster nodesEPSS 0.2%CVE-2025-13352LOWMattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijackingEPSS 0.2%CVE-2025-9072HIGHOne-Click Mattermost Account Takeover via Poisoned RelayState SAML ParameterEPSS 0.2%CVE-2026-4635MEDIUMPersistent notification timing attack causing server denial of serviceEPSS 0.2%CVE-2025-9084LOWOpen redirect in OAuth loginEPSS 0.2%CVE-2026-8821HIGHPlaybooks run owner channel membership permission bypassEPSS 0.2%CVE-2026-4643LOWCalling window.close() from server-side content causes crash in the Mattermost Desktop AppEPSS 0.2%CVE-2026-2463MEDIUMUnauthorized access to invite ID during team creationEPSS 0.2%CVE-2026-16044LOWInsufficient validation of guest board admin privileges on archive importEPSS 0.2%CVE-2025-1398LOWmacOS TCC Bypass via Code InjectionEPSS 0.2%CVE-2025-55074LOWChannel member objects leak read statusEPSS 0.2%CVE-2025-14350MEDIUMInformation disclosure via channel mentions in postsEPSS 0.2%CVE-2025-41436LOWUnauthorized access to archived channel content via threads interfaceEPSS 0.2%CVE-2026-27769LOWConnected Workspaces: Malicious remote server can manipulate arbitrary user's statusEPSS 0.2%CVE-2026-75588LOWMattermost Desktop App plugin popout scheme validation bypassEPSS 0.2%CVE-2026-2456MEDIUMDenial of Service via Unbounded Memory Allocation in Integration ActionsEPSS 0.2%CVE-2026-24692MEDIUMGuest users can bypass read permissions via search APIEPSS 0.2%CVE-2026-2455MEDIUMSSRF bypass via IPv4-mapped IPv6 literalsEPSS 0.2%CVE-2026-2458MEDIUMUnauthorized channel enumeration in private teams after member removalEPSS 0.2%CVE-2026-6343MEDIUMMattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing unauthorized access to public playbooksEPSS 0.2%