Exposição de Mattermost
Message boards44
score de exposição
2
sites usam
0
em exploração
6
críticos
CVEs
454 resultadosCVE-2024-4198LOWMattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authentiEPSS 0.5%CVE-2024-4195LOWMattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authentEPSS 0.5%CVE-2023-27263MEDIUMIDOR: Accessing playbook runs via the Playbooks Runs APIEPSS 0.5%CVE-2023-5330MEDIUM Denial of Service via Opengraph Data CacheEPSS 0.5%CVE-2025-36530MEDIUMImport Path Traversal Enables Unauthorized Unsigned Plugin InstallationEPSS 0.5%CVE-2023-5333MEDIUM Denial of Service via multiple identical User IDs in /api/v4/users/idsEPSS 0.5%CVE-2025-41395MEDIUMWebapp DoS via malicious retrospective post in PlaybooksEPSS 0.5%CVE-2023-2281LOWArchiving a team broadcasts unsanitized data over WebSocketsEPSS 0.5%CVE-2023-5193MEDIUMSystem Role with manage posts permission can read posts of Direct MessagesEPSS 0.5%CVE-2023-2515MEDIUMPrivilege escalation to system admin via personal access tokensEPSS 0.5%CVE-2024-11599HIGHDomain Restriction Bypass on RegistrationEPSS 0.5%CVE-2024-3872LOWMattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which alloEPSS 0.5%CVE-2023-1562LOWFull name revealed via /plugins/focalboard/api/v2/usersEPSS 0.5%CVE-2023-7114HIGHMattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.EPSS 0.5%CVE-2024-39832MEDIUMPermanently local data deletion by malicious remoteEPSS 0.5%CVE-2024-47401MEDIUMDoS via Amplified GraphQL Response in PlaybooksEPSS 0.5%CVE-2026-9699MEDIUMMattermost Agents plugin logs unsanitized OpenAI API keys on authentication errorsEPSS 0.5%CVE-2025-20621MEDIUMWebapp crash via object that can't be cast to String in Attachment FieldEPSS 0.5%CVE-2023-48732MEDIUMKeywords that trigger mentions are leaked to other usersEPSS 0.5%CVE-2024-39810MEDIUMServer crash via Elasticsearch certificate fileEPSS 0.5%