Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
4.9
CVE-2026-6957
- EPSS 0.3%
- Veröffentlicht 27.05.2026 15:16:34
- Zuletzt bearbeitet 02.06.2026 14:29:03
Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary lo...
8.8
CVE-2026-3524
- EPSS 0.38%
- Veröffentlicht 06.04.2026 12:06:22
- Zuletzt bearbeitet 06.08.2026 14:21:13
Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to t...
1