Mattermost

Mattermost

245 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 16.03.2026 12:04:18
  • Zuletzt bearbeitet 18.03.2026 18:11:16

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advis...

  • EPSS 0.06%
  • Veröffentlicht 16.03.2026 12:02:23
  • Zuletzt bearbeitet 18.03.2026 18:14:11

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Matter...

  • EPSS 0.18%
  • Veröffentlicht 16.03.2026 12:00:21
  • Zuletzt bearbeitet 18.03.2026 18:31:45

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltr...

  • EPSS 0.03%
  • Veröffentlicht 16.03.2026 11:58:09
  • Zuletzt bearbeitet 18.03.2026 17:42:38

Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory...

  • EPSS 0.05%
  • Veröffentlicht 16.03.2026 11:33:02
  • Zuletzt bearbeitet 18.03.2026 18:03:54

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a...

  • EPSS 0.03%
  • Veröffentlicht 16.03.2026 11:27:49
  • Zuletzt bearbeitet 18.03.2026 17:48:32

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel se...

  • EPSS 0.02%
  • Veröffentlicht 16.03.2026 11:20:25
  • Zuletzt bearbeitet 18.03.2026 17:49:10

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post...

  • EPSS 0.03%
  • Veröffentlicht 16.03.2026 11:16:32
  • Zuletzt bearbeitet 20.03.2026 18:30:35

Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermo...

  • EPSS 0.02%
  • Veröffentlicht 16.03.2026 11:13:57
  • Zuletzt bearbeitet 18.03.2026 17:43:26

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs...

  • EPSS 0.03%
  • Veröffentlicht 16.03.2026 11:11:07
  • Zuletzt bearbeitet 20.03.2026 18:29:11

Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-0...