Exposição de Mattermost
Message boards44
score de exposição
2
sites usam
0
em exploração
6
críticos
CVEs
454 resultadosCVE-2024-24774LOWMissing authorization allows users to access arbitrary security levels on Jira through webhooks (Jira Plugin)EPSS 0.5%CVE-2024-32046MEDIUMDetailed error discloses full file path with dev mode offEPSS 0.5%CVE-2023-1776HIGHStored XSS via SVG attachment on BoardsEPSS 0.4%CVE-2024-2446MEDIUMMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentioEPSS 0.4%CVE-2024-54682MEDIUMZipbomb DoS via Missing Slack Import ValidationEPSS 0.4%CVE-2023-6202MEDIUMInsecure Direct Object Reference in /plugins/focalboard/ api/v2/users of Mattermost BoardsEPSS 0.4%CVE-2025-24490CRITICALSQL Injection in Mattermost Boards via board category ID reorderingEPSS 0.4%CVE-2023-46701MEDIUMInaccessible Post Information Leak via Run Timeline IDOREPSS 0.4%CVE-2023-3587LOWInconsistent state in UI after boards permission change by system adminEPSS 0.4%CVE-2024-43105MEDIUMExcessive Resource Consumption via `/export`EPSS 0.4%CVE-2023-3590LOWDeleted attachments in Boards remain accessibleEPSS 0.4%CVE-2025-20086MEDIUMInsufficient Input Validation on Post PropsEPSS 0.4%CVE-2026-3112MEDIUMArbitrary File Read via Advanced Logging Support PacketEPSS 0.4%CVE-2023-1831HIGHUser password logged in audit logsEPSS 0.4%CVE-2026-6850MEDIUMCrafted message attachment causes client-side denial of service via markdown parser regex backtracking in MattermostEPSS 0.4%CVE-2026-8075MEDIUMPosting a malicious markdown image crashes the Mattermost Desktop AppEPSS 0.4%CVE-2026-9602MEDIUMMattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methodsEPSS 0.4%CVE-2023-5195MEDIUMA team member can soft delete other teams that they are not part ofEPSS 0.4%CVE-2023-47865MEDIUMUsername and Icon override can be used by members when Hardened Mode is enabledEPSS 0.4%CVE-2025-58073HIGHArbitrary Mattermost Team can be joined by manipulating the OAuth stateEPSS 0.4%