Skip to content
Noroxi

winfunc

12 credited records · 12 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • CVE-2026-7521
    22Monitor

    SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory

    MediumCVSS 5.5No exploitEPSS 0%

    mattermost · mattermost serverJul 28, 2026

  • CVE-2026-9162
    17Monitor

    Global session revocation does not invalidate active WebSocket connections

    MediumCVSS 4.3No exploitEPSS 0%

    mattermost · mattermost serverJun 22, 2026

  • CVE-2026-7387
    35Monitor

    Mattermost group syncable endpoints allow privilege escalation via scheme_admin

    HighCVSS 8.8No exploitEPSS 0%

    mattermost · mattermost serverJun 12, 2026

  • CVE-2026-7184
    26Monitor

    Mattermost Remote Cluster PATCH API Leaks Authentication Tokens

    MediumCVSS 6.5No exploitEPSS 0%

    mattermost · mattermost serverJun 12, 2026

  • CVE-2026-3115
    17Monitor

    Guest users can view group member IDs without respecting view restrictions

    MediumCVSS 4.3No exploitEPSS 0%

    mattermost · mattermost serverMar 26, 2026

  • CVE-2026-3114
    26Monitor

    Zip Bomb Denial of Service via Unrestricted Archive Decompression

    MediumCVSS 6.5No exploitEPSS 0%

    mattermost · mattermost serverMar 26, 2026

  • CVE-2026-3113
    22Monitor

    mmctl export download command doesn’t restrict permissions to created file to file owner

    MediumCVSS 5.5No exploitEPSS 0%

    mattermost · mattermost serverMar 26, 2026

  • CVE-2026-3108
    35Monitor

    Terminal Escape Injection in mmctl Report Posts Command

    HighCVSS 8.8No exploitEPSS 0%

    mattermost · mattermost serverMar 26, 2026

  • CVE-2026-2455
    17Monitor

    SSRF bypass via IPv4-mapped IPv6 literals

    MediumCVSS 4.3No exploitEPSS 0%

    mattermost · mattermost serverMar 16, 2026

  • Private channel enumeration via /mute slash command

    MediumCVSS 4.3No exploitEPSS 0%

    mattermost · mattermost serverMar 16, 2026

  • Denial of service via malformed User-Agent header in getBrowserVersion

    MediumCVSS 4.3No exploitEPSS 0%

    mattermost · mattermost serverMar 16, 2026

  • DoS attack via login attempts with multi-megabyte passwords

    HighCVSS 7.5No exploitEPSS 0%

    mattermost · mattermost serverMar 16, 2026