| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-32046 | Detailed error discloses full file path with dev mode off | Mattermost | Mattermost | Medium | 4.3 | 2024-04-26 08:24:51 | Deep Dive |
| CVE-2024-22091 | Excessive resource consumption due to lack to request path size limits | Mattermost | Mattermost | Low | 3.1 | 2024-04-26 08:24:34 | Deep Dive |
| CVE-2024-3872 | Mattermost Mobile Apps 安全漏洞 | Mattermost | Mattermost | Low | 3.1 | 2024-04-16 09:05:05 | Deep Dive |
| CVE-2024-2447 | Mattermost 安全漏洞 | Mattermost | Mattermost | Medium | 6.5 | 2024-04-05 08:53:00 | Deep Dive |
| CVE-2024-29221 | Invite ID available to team admins even without the "Add Members" permission | Mattermost | Mattermost | Medium | 4.7 | 2024-04-05 08:15:07 | Deep Dive |
| CVE-2024-28949 | DoS via a large number of User Preferences | Mattermost | Mattermost | Medium | 4.3 | 2024-04-05 08:14:10 | Deep Dive |
| CVE-2024-21848 | Users maintain access to active call after being removed from a channel | Mattermost | Mattermost | Low | 3.1 | 2024-04-05 08:13:02 | Deep Dive |
| CVE-2024-2445 | Reflected XSS in Mattermost Jira plugin | Mattermost | Mattermost | Medium | 6.1 | 2024-03-15 09:19:50 | Deep Dive |
| CVE-2024-2450 | Mattermost 安全漏洞 | Mattermost | Mattermost | High | 8.8 | 2024-03-15 09:12:29 | Deep Dive |
| CVE-2024-2446 | Mattermost 安全漏洞 | Mattermost | Mattermost | Medium | 4.3 | 2024-03-15 09:11:21 | Deep Dive |
| CVE-2024-28053 | Resource Exhaustion via the Invitation Feature | Mattermost | Mattermost | Low | 3.1 | 2024-03-15 09:08:05 | Deep Dive |
| CVE-2024-24975 | Denial of Service for mobile app users due to automatic code highlighting | Mattermost | Mattermost Mobile | Low | 3.5 | 2024-03-15 09:07:13 | Deep Dive |
| CVE-2024-1953 | Mattermost 安全漏洞 | Mattermost | Mattermost | Medium | 4.3 | 2024-02-29 10:42:42 | Deep Dive |
| CVE-2024-1952 | Mattermost 安全漏洞 | Mattermost | Mattermost | Low | 3.1 | 2024-02-29 10:42:15 | Deep Dive |
| CVE-2024-1949 | Mattermost 安全漏洞 | Mattermost | Mattermost | Low | 2.6 | 2024-02-29 10:41:55 | Deep Dive |
| CVE-2024-1942 | Mattermost 安全漏洞 | Mattermost | Mattermost | Medium | 4.3 | 2024-02-29 10:41:38 | Deep Dive |
| CVE-2024-1888 | Existing server guests invited to the team by members without "invite_guest" permission | Mattermost | Mattermost | Medium | 4.3 | 2024-02-29 08:08:08 | Deep Dive |
| CVE-2024-24988 | Excessive resource consumption when sending long emoji names in user custom status | Mattermost | Mattermost | Medium | 4.3 | 2024-02-29 08:06:28 | Deep Dive |
| CVE-2024-1887 | Public channel post content accessible without membership when compliance export is enabled | Mattermost | Mattermost | Medium | 4.3 | 2024-02-29 08:05:30 | Deep Dive |
| CVE-2024-23488 | Files of archived channels accessible with the “Allow users to view archived channels” option disabled | Mattermost | Mattermost | Low | 3.1 | 2024-02-29 08:03:21 | Deep Dive |