winfunc
12 credited records · 12 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
22Monitor | CVE-2026-7521No exploit | SAML certificate deletion allows path traversal to delete arbitrary files outside the config directorymattermost · mattermost server · CWE-22 | Medium5.5 | — | 0.4% | Jul 28, 2026 |
17Monitor | CVE-2026-9162No exploit | Global session revocation does not invalidate active WebSocket connectionsmattermost · mattermost server · CWE-613 | Medium4.3 | — | 0.3% | Jun 22, 2026 |
35Monitor | CVE-2026-7387No exploit | Mattermost group syncable endpoints allow privilege escalation via scheme_adminmattermost · mattermost server · CWE-863 | High8.8 | — | 0.4% | Jun 12, 2026 |
26Monitor | CVE-2026-7184No exploit | Mattermost Remote Cluster PATCH API Leaks Authentication Tokensmattermost · mattermost server · CWE-201 | Medium6.5 | — | 0.4% | Jun 12, 2026 |
17Monitor | CVE-2026-3115No exploit | Guest users can view group member IDs without respecting view restrictionsmattermost · mattermost server · CWE-863 | Medium4.3 | — | 0.3% | Mar 26, 2026 |
26Monitor | CVE-2026-3114No exploit | Zip Bomb Denial of Service via Unrestricted Archive Decompressionmattermost · mattermost server · CWE-409 | Medium6.5 | — | 0.4% | Mar 26, 2026 |
22Monitor | CVE-2026-3113No exploit | mmctl export download command doesn’t restrict permissions to created file to file ownermattermost · mattermost server · CWE-732 | Medium5.5 | — | 0.1% | Mar 26, 2026 |
35Monitor | CVE-2026-3108No exploit | Terminal Escape Injection in mmctl Report Posts Commandmattermost · mattermost server · CWE-150 | High8.8 | — | 0.3% | Mar 26, 2026 |
17Monitor | CVE-2026-2455No exploit | SSRF bypass via IPv4-mapped IPv6 literalsmattermost · mattermost server · CWE-918 | Medium4.3 | — | 0.2% | Mar 16, 2026 |
17Monitor | CVE-2026-21386No exploit | Private channel enumeration via /mute slash commandmattermost · mattermost server · CWE-203 | Medium4.3 | — | 0.2% | Mar 16, 2026 |
17Monitor | CVE-2026-25783No exploit | Denial of service via malformed User-Agent header in getBrowserVersionmattermost · mattermost server · CWE-1287 | Medium4.3 | — | 0.4% | Mar 16, 2026 |
30Monitor | CVE-2026-24458No exploit | DoS attack via login attempts with multi-megabyte passwordsmattermost · mattermost server · CWE-770 | High7.5 | — | 0.3% | Mar 16, 2026 |
- CVE-2026-752122Monitor
SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory
MediumCVSS 5.5No exploitEPSS 0%mattermost · mattermost serverJul 28, 2026
- CVE-2026-916217Monitor
Global session revocation does not invalidate active WebSocket connections
MediumCVSS 4.3No exploitEPSS 0%mattermost · mattermost serverJun 22, 2026
- CVE-2026-738735Monitor
Mattermost group syncable endpoints allow privilege escalation via scheme_admin
HighCVSS 8.8No exploitEPSS 0%mattermost · mattermost serverJun 12, 2026
- CVE-2026-718426Monitor
Mattermost Remote Cluster PATCH API Leaks Authentication Tokens
MediumCVSS 6.5No exploitEPSS 0%mattermost · mattermost serverJun 12, 2026
- CVE-2026-311517Monitor
Guest users can view group member IDs without respecting view restrictions
MediumCVSS 4.3No exploitEPSS 0%mattermost · mattermost serverMar 26, 2026
- CVE-2026-311426Monitor
Zip Bomb Denial of Service via Unrestricted Archive Decompression
MediumCVSS 6.5No exploitEPSS 0%mattermost · mattermost serverMar 26, 2026
- CVE-2026-311322Monitor
mmctl export download command doesn’t restrict permissions to created file to file owner
MediumCVSS 5.5No exploitEPSS 0%mattermost · mattermost serverMar 26, 2026
- CVE-2026-310835Monitor
Terminal Escape Injection in mmctl Report Posts Command
HighCVSS 8.8No exploitEPSS 0%mattermost · mattermost serverMar 26, 2026
- CVE-2026-245517Monitor
SSRF bypass via IPv4-mapped IPv6 literals
MediumCVSS 4.3No exploitEPSS 0%mattermost · mattermost serverMar 16, 2026
- CVE-2026-2138617Monitor
Private channel enumeration via /mute slash command
MediumCVSS 4.3No exploitEPSS 0%mattermost · mattermost serverMar 16, 2026
- CVE-2026-2578317Monitor
Denial of service via malformed User-Agent header in getBrowserVersion
MediumCVSS 4.3No exploitEPSS 0%mattermost · mattermost serverMar 16, 2026
- CVE-2026-2445830Monitor
DoS attack via login attempts with multi-megabyte passwords
HighCVSS 7.5No exploitEPSS 0%mattermost · mattermost serverMar 16, 2026