Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
713 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.8) | 0.26% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost… | |
| Analizada | Media (4.3) | 0.25% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID.… | |
| Analizada | Media (4.9) | 0.36% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming… | |
| Analizada | Media (5.4) | 0.23% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory… | |
| Analizada | Media (6.5) | 0.30% | — | Mattermost Server | 13/7/2026 | 15/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint..… | |
| Analizada | Media (6.5) | 0.42% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers… | |
| Analizada | Media (6.5) | 0.30% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a… | |
| Analizada | Media (4.3) | 0.24% | — | Mattermost Server | 13/7/2026 | 14/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs… | |
| Analizada | Media (5.4) | 0.29% | — | Mattermost Server | 13/7/2026 | 14/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel… | |
| Pendiente de análisis | Media (5.9) | 0.33% | — | Drupal RAW FormatterAI | 10/7/2026 | 13/7/2026 | vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. | |
| Analizada | Crítica (9.8) | 0.56% | — | Zroger Formatter Field | 10/7/2026 | 6/8/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | PerfmattersAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions. | |
| Aplazada | Alta (7.5) | 0.94% | — | PerfmattersAI | 2/7/2026 | 2/7/2026 | The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the… | |
| Pendiente de análisis | Media (6.8) | 0.46% | — | MattermostAI | 26/6/2026 | 26/6/2026 | Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of mattermost.log entries generated during… | |
| Aplazada | Alta (7.1) | 0.25% | — | PerfmattersAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions. | |
| Analizada | Media (6.5) | 0.14% | — | Mattermost Server | 26/6/2026 | 29/6/2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate… | |
| Analizada | Baja (3.5) | 0.27% | — | Mattermost Server | 26/6/2026 | 29/6/2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown image syntax into tool result content… | |
| Pendiente de análisis | Media (5.4) | 0.29% | — | MattermostAI | 26/6/2026 | 26/6/2026 | The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Advisory ID:… | |
| Analizada | Media (4.3) | 0.20% | — | Mattermost Google Drive | 25/6/2026 | 11/8/2026 | The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. | |
| Analizada | Baja (3.8) | 0.32% | — | Mattermost Server | 22/6/2026 | 26/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669 | |
| Analizada | Media (4.3) | 0.33% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connections during global session revocation, which allows a user with an existing WebSocket connection to remain authenticated and continue receiving… | |
| Analizada | Baja (3.8) | 0.32% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint..… | |
| Analizada | Media (6.4) | 0.30% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret and disrupt the Jira integration via POST to /ac/installed during the pending-install… | |
| Analizada | Media (6.4) | 0.24% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subscription before applying edits which allows an authenticated attacker to hijack subscriptions from channels they have no access to via a crafted PUT request to the… | |
| Analizada | Media (5.4) | 0.29% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler, which allows any authenticated user to overwrite the global default GitLab instance configuration… |