Slack records
3 published records for vendor slack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-347 Improper Verification of Cryptographic Signature1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
Bug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2020-11498No exploit | Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of thslack · nebula · CWE-22 | High8.8 | — | 3.4% | Apr 2, 2020 |
31Monitor | CVE-2019-14366No exploit | WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code.slack · wp slacksync · CWE-200 | High7.5 | — | 1.7% | Nov 12, 2019 |
30Monitor | CVE-2026-25793No exploit | Nebula Has Possible Blocklist Bypass via ECDSA Signature Malleabilityslack · nebula · CWE-347 | High7.6 | — | 0.2% | Feb 6, 2026 |
- CVE-2020-1149836Monitor
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of th
HighCVSS 8.8No exploitEPSS 3%slack · nebulaApr 2, 2020
- CVE-2019-1436631Monitor
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code.
HighCVSS 7.5No exploitEPSS 2%slack · wp slacksyncNov 12, 2019
- CVE-2026-2579330Monitor
Nebula Has Possible Blocklist Bypass via ECDSA Signature Malleability
HighCVSS 7.6No exploitEPSS 0%slack · nebulaFeb 6, 2026