Exposição de Mattermost
Message boards44
score de exposição
2
sites usam
0
em exploração
6
críticos
CVEs
454 resultadosCVE-2026-6689MEDIUM*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings*EPSS 0.2%CVE-2026-4055MEDIUMInsufficient permission validation on cross-team playbook run creationEPSS 0.2%CVE-2026-16046LOWMissing run-state validation on finished playbook runsEPSS 0.2%CVE-2025-9078MEDIUMWeak cache keys lead to post IDOR and link preview poisoningEPSS 0.2%CVE-2026-15754MEDIUMMissing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removalEPSS 0.1%CVE-2026-3473MEDIUMImproper file ownership validation in the Boards API allows unauthorised file accessEPSS 0.1%CVE-2025-62690LOWOpen redirect in error page when link opened in new tabEPSS 0.1%CVE-2026-22545LOWPassword Change Bypass via Auth Switch EndpointEPSS 0.1%CVE-2026-75025MEDIUMMattermost Desktop local network access from server-rendered contentEPSS 0.1%CVE-2026-3590MEDIUMRace Condition in Guest Magic Link Authentication Allows Token ReuseEPSS 0.1%CVE-2025-59480MEDIUMInadequate validation of SSO redirect credentials permits credential theftEPSS 0.1%CVE-2023-5339MEDIUMMattermost Desktop logs all keystrokes during initial run after fresh installation EPSS 0.1%CVE-2026-3495LOWUnescaped variables during error page compositionEPSS 0.1%CVE-2026-4286LOWPlaybooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook updateEPSS 0.1%CVE-2026-4273LOWInsufficient token rotation validation in remote cluster invite confirmationEPSS 0.1%CVE-2026-4274MEDIUMInsufficient authorization in shared channel membership sync grants team-level access instead of channel-level accessEPSS 0.1%CVE-2026-4339MEDIUMSSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP serverEPSS 0.1%CVE-2026-28735MEDIUMGitHub OAuth Scope ValidationEPSS 0.1%CVE-2026-6333LOWSSRF via Host Header Spoofing in Custom Slash CommandsEPSS 0.1%CVE-2026-1628MEDIUMMattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.EPSS 0.1%