Записи Mattermost
623 опубликованных записей вендора mattermost.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 57,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-863 Incorrect Authorization83
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor51
- CWE-862 Missing Authorization48
- CWE-284 Improper Access Control47
- CWE-400 Uncontrolled Resource Consumption44
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')24
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
623 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-20853Эксплойта нет | An issue was discovered in Mattermost Packages before 5.16.3.mattermost · mattermost packages · CWE-668 | Критическая9,8 | — | 2,2 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2019-20856Эксплойта нет | An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS.mattermost · mattermost desktop · CWE-427 | Критическая9,8 | — | 1,4 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2017-18912Эксплойта нет | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7.mattermost · mattermost server · CWE-22 | Критическая9,8 | — | 1,4 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2017-18900Эксплойта нет | An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3.mattermost · mattermost server · CWE-74 | Критическая9,8 | — | 1,3 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2016-11064Эксплойта нет | An issue was discovered in Mattermost Desktop App before 3.4.0.mattermost · mattermost desktop · CWE-94 | Критическая9,8 | — | 1,3 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2017-18920Эксплойта нет | An issue was discovered in Mattermost Server before 3.6.2.mattermost · mattermost server | Критическая9,8 | — | 1,2 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2018-21251Эксплойта нет | An issue was discovered in Mattermost Server before 5.2 and 5.1.1.mattermost · mattermost server · CWE-862 | Критическая9,8 | — | 1,2 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2017-18908Эксплойта нет | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2.mattermost · mattermost server · CWE-287 | Критическая9,8 | — | 1,2 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2017-18885Эксплойта нет | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2.mattermost · mattermost server · CWE-269 | Критическая9,8 | — | 1,2 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2016-11074Эксплойта нет | An issue was discovered in Mattermost Server before 3.0.0.mattermost · mattermost server · CWE-287 | Критическая9,8 | — | 1,2 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2017-18915Эксплойта нет | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7.mattermost · mattermost server · CWE-276 | Критическая9,8 | — | 1,2 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2017-18888Эксплойта нет | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2.mattermost · mattermost server · CWE-89 | Критическая9,8 | — | 1,1 % | 19 июн. 2020 г. |
39Наблюдать | CVE-2025-4981Эксплойта нет | Path Traversal Leading to RCE by Any Authenticated Mattermost Usermattermost · mattermost server · CWE-427 | Критическая9,9 | — | 0,8 % | 20 июн. 2025 г. |
39Наблюдать | CVE-2023-6458Эксплойта нет | Client side path traversal due to lack of route parameters validationmattermost · mattermost server · CWE-74 | Критическая9,8 | — | 0,6 % | 6 дек. 2023 г. |
39Наблюдать | CVE-2026-4858Эксплойта нет | Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.mattermost · mattermost server · CWE-22 | Критическая9,9 | — | 0,4 % | 21 мая 2026 г. |
39Наблюдать | CVE-2025-12421Эксплойта нет | Account Takeover via Code Exchange Endpointmattermost · mattermost server · CWE-303 | Критическая9,9 | — | 0,3 % | 27 нояб. 2025 г. |
39Наблюдать | CVE-2025-12419Эксплойта нет | Account takeover on OAuth/OpenID-enabled serversmattermost · mattermost server · CWE-303 | Критическая9,9 | — | 0,3 % | 27 нояб. 2025 г. |
38Наблюдать | CVE-2024-39777Эксплойта нет | Malicious remote can invite itself to an arbitrary local channelmattermost · mattermost · CWE-284 | Критическая9,6 | — | 0,4 % | 1 авг. 2024 г. |
37Наблюдать | CVE-2025-25279Proof of concept | Arbitrary file read in Mattermost Boards via import & export board archivemattermost · mattermost server · CWE-22 | Высокая7,5 | — | 24,0 % | 24 февр. 2025 г. |
36Наблюдать | CVE-2019-20851Эксплойта нет | An issue was discovered in Mattermost Mobile Apps before 1.26.0.mattermost · mattermost · CWE-22 | Критическая9,1 | — | 1,4 % | 19 июн. 2020 г. |
36Наблюдать | CVE-2017-18883Эксплойта нет | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider.mattermost · mattermost server · CWE-331 | Критическая9,1 | — | 1,1 % | 19 июн. 2020 г. |
36Наблюдать | CVE-2017-18911Эксплойта нет | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7.mattermost · mattermost server · CWE-295 | Критическая9,1 | — | 0,7 % | 19 июн. 2020 г. |
36Наблюдать | CVE-2023-2193Эксплойта нет | Oauth authorization codes do not expire when deauthorizing an oauth2 appmattermost · mattermost · CWE-862 | Критическая9,1 | — | 0,6 % | 20 апр. 2023 г. |
35Наблюдать | CVE-2019-20861Эксплойта нет | An issue was discovered in Mattermost Desktop App before 4.2.2.mattermost · mattermost desktop | Высокая8,8 | — | 1,7 % | 19 июн. 2020 г. |
35Наблюдать | CVE-2018-21264Эксплойта нет | An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2.mattermost · mattermost server · CWE-20 | Высокая8,8 | — | 1,1 % | 19 июн. 2020 г. |
- CVE-2019-2085340В плане
An issue was discovered in Mattermost Packages before 5.16.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mattermost · mattermost packages19 июн. 2020 г.
- CVE-2019-2085639Наблюдать
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost desktop19 июн. 2020 г.
- CVE-2017-1891239Наблюдать
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2017-1890039Наблюдать
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2016-1106439Наблюдать
An issue was discovered in Mattermost Desktop App before 3.4.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost desktop19 июн. 2020 г.
- CVE-2017-1892039Наблюдать
An issue was discovered in Mattermost Server before 3.6.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2018-2125139Наблюдать
An issue was discovered in Mattermost Server before 5.2 and 5.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2017-1890839Наблюдать
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2017-1888539Наблюдать
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2016-1107439Наблюдать
An issue was discovered in Mattermost Server before 3.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2017-1891539Наблюдать
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2017-1888839Наблюдать
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2025-498139Наблюдать
Path Traversal Leading to RCE by Any Authenticated Mattermost User
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %mattermost · mattermost server20 июн. 2025 г.
- CVE-2023-645839Наблюдать
Client side path traversal due to lack of route parameters validation
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mattermost · mattermost server6 дек. 2023 г.
- CVE-2026-485839Наблюдать
Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %mattermost · mattermost server21 мая 2026 г.
- CVE-2025-1242139Наблюдать
Account Takeover via Code Exchange Endpoint
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %mattermost · mattermost server27 нояб. 2025 г.
- CVE-2025-1241939Наблюдать
Account takeover on OAuth/OpenID-enabled servers
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %mattermost · mattermost server27 нояб. 2025 г.
- CVE-2024-3977738Наблюдать
Malicious remote can invite itself to an arbitrary local channel
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %mattermost · mattermost1 авг. 2024 г.
- CVE-2025-2527937Наблюдать
Arbitrary file read in Mattermost Boards via import & export board archive
ВысокаяCVSS 7,5Proof of conceptEPSS 24 %mattermost · mattermost server24 февр. 2025 г.
- CVE-2019-2085136Наблюдать
An issue was discovered in Mattermost Mobile Apps before 1.26.0.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %mattermost · mattermost19 июн. 2020 г.
- CVE-2017-1888336Наблюдать
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2017-1891136Наблюдать
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2023-219336Наблюдать
Oauth authorization codes do not expire when deauthorizing an oauth2 app
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %mattermost · mattermost20 апр. 2023 г.
- CVE-2019-2086135Наблюдать
An issue was discovered in Mattermost Desktop App before 4.2.2.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mattermost · mattermost desktop19 июн. 2020 г.
- CVE-2018-2126435Наблюдать
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mattermost · mattermost server19 июн. 2020 г.