Exposição de Mattermost
Message boards52
score de exposição
1
sites usam
0
em exploração
6
críticos
CVEs
421 resultadosCVE-2023-27263MEDIUMIDOR: Accessing playbook runs via the Playbooks Runs APIEPSS 0.5%CVE-2023-5330MEDIUM Denial of Service via Opengraph Data CacheEPSS 0.5%CVE-2025-36530MEDIUMImport Path Traversal Enables Unauthorized Unsigned Plugin InstallationEPSS 0.5%CVE-2023-5333MEDIUM Denial of Service via multiple identical User IDs in /api/v4/users/idsEPSS 0.5%CVE-2023-2281LOWArchiving a team broadcasts unsanitized data over WebSocketsEPSS 0.5%CVE-2023-5193MEDIUMSystem Role with manage posts permission can read posts of Direct MessagesEPSS 0.5%CVE-2023-2515MEDIUMPrivilege escalation to system admin via personal access tokensEPSS 0.5%CVE-2024-3872LOWMattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which alloEPSS 0.5%CVE-2023-1562LOWFull name revealed via /plugins/focalboard/api/v2/usersEPSS 0.5%CVE-2024-11599HIGHDomain Restriction Bypass on RegistrationEPSS 0.5%CVE-2023-7114HIGHMattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.EPSS 0.5%CVE-2024-39832MEDIUMPermanently local data deletion by malicious remoteEPSS 0.5%CVE-2025-41395MEDIUMWebapp DoS via malicious retrospective post in PlaybooksEPSS 0.5%CVE-2024-47401MEDIUMDoS via Amplified GraphQL Response in PlaybooksEPSS 0.5%CVE-2023-48732MEDIUMKeywords that trigger mentions are leaked to other usersEPSS 0.5%CVE-2024-39810MEDIUMServer crash via Elasticsearch certificate fileEPSS 0.5%CVE-2024-24774LOWMissing authorization allows users to access arbitrary security levels on Jira through webhooks (Jira Plugin)EPSS 0.5%CVE-2024-32046MEDIUMDetailed error discloses full file path with dev mode offEPSS 0.5%CVE-2025-20621MEDIUMWebapp crash via object that can't be cast to String in Attachment FieldEPSS 0.4%CVE-2023-1776HIGHStored XSS via SVG attachment on BoardsEPSS 0.4%