Vulnerabilidades em Mattermost

489 resultados
Análise Vexday

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2026-3112MEDIUMArbitrary File Read via Advanced Logging Support PacketEPSS 0.4%CVE-2026-9602MEDIUMMattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methodsEPSS 0.4%CVE-2026-6850MEDIUMCrafted message attachment causes client-side denial of service via markdown parser regex backtracking in MattermostEPSS 0.4%CVE-2023-1831HIGHUser password logged in audit logsEPSS 0.4%CVE-2026-8075MEDIUMPosting a malicious markdown image crashes the Mattermost Desktop AppEPSS 0.4%CVE-2023-5195MEDIUMA team member can soft delete other teams that they are not part ofEPSS 0.4%CVE-2023-47865MEDIUMUsername and Icon override can be used by members when Hardened Mode is enabledEPSS 0.4%CVE-2025-58073HIGHArbitrary Mattermost Team can be joined by manipulating the OAuth stateEPSS 0.4%CVE-2023-1421LOWReflected XSS in OAuth flow completion endpointsEPSS 0.4%CVE-2023-6727LOWLeak Inaccessible Playbook Information via Channel Action IDOREPSS 0.4%CVE-2023-2808MEDIUMLack of URL normalization allows rendering previews for disallowed domainsEPSS 0.4%CVE-2025-8023MEDIUMPath Traversal in Template Upload Allows Uploading Files Outside Target DirectoryEPSS 0.4%CVE-2024-24975LOW Denial of Service for mobile app users due to automatic code highlightingEPSS 0.4%CVE-2023-47168MEDIUMOpen redirect in /oauth/<service>/mobile_login?redirect_to=EPSS 0.4%CVE-2023-2791MEDIUMPlaybooks lets you edit arbitrary postsEPSS 0.4%CVE-2023-4105LOWAttachment of deleted message in a thread remains accessible and downloadable EPSS 0.4%CVE-2025-35965MEDIUMDoS in Mattermost Playbooks via Excessive Task ActionsEPSS 0.4%CVE-2024-6428MEDIUMLimited DoS due to permitting creating users with user-defined IDsEPSS 0.4%CVE-2024-40884LOWUnauthorized disabling of invite URLEPSS 0.4%CVE-2024-23493MEDIUM Team associated AD/LDAP Groups Leaked due to missing authorizationEPSS 0.4%