Exposição de Mattermost

Message boards
52
score de exposição
1
sites usam
0
em exploração
6
críticos

CVEs

421 resultados
CVE-2023-5160MEDIUMFull name disclosure via team top membership with Show Full Name option disabledEPSS 0.4%CVE-2023-47858MEDIUMDetails of archived public channels are leaked to members of another teamEPSS 0.4%CVE-2025-0476MEDIUMMobile crash via file with specially crafted filenameEPSS 0.4%CVE-2025-1558MEDIUMDenial of Service Via Malicious GIFEPSS 0.4%CVE-2023-3582MEDIUMLack of channel membership check when linking a board to a channelEPSS 0.4%CVE-2023-2786MEDIUMChannel commands execution doesn't properly verify permissionsEPSS 0.4%CVE-2023-3614MEDIUMDenial of Service via specially crafted gif imageEPSS 0.4%CVE-2026-20719MEDIUMDoS via URL Previews Rendering Malicious SVGsEPSS 0.4%CVE-2023-3584LOWMember can create team with team override scheme EPSS 0.4%CVE-2025-12419CRITICALAccount takeover on OAuth/OpenID-enabled serversEPSS 0.3%CVE-2025-12421CRITICALAccount Takeover via Code Exchange EndpointEPSS 0.3%CVE-2024-39807LOWChannel IDs of archived/restored channels leaked via webhook eventsEPSS 0.3%CVE-2026-3116MEDIUMImproper Input Validation in Zoom Plugin Webhook HandlerEPSS 0.3%CVE-2024-8071MEDIUMSystem Role with edit access to permissions can elevate themselves to system adminEPSS 0.3%CVE-2026-3114MEDIUMZip Bomb Denial of Service via Unrestricted Archive DecompressionEPSS 0.3%CVE-2024-42497MEDIUMInsufficient permissions checks on teamsEPSS 0.3%CVE-2024-39274HIGHMalicious remote can add users to arbitrary teams and channelsEPSS 0.3%CVE-2026-5740HIGHUnauthenticated WebSocket binary frame causes denial of service in Mattermost ServerEPSS 0.3%CVE-2025-25274MEDIUMUnauthorized Command Execution in Archived ChannelsEPSS 0.3%CVE-2023-3591MEDIUMLack of previous password reset tokens on new token creationEPSS 0.3%