VYPR

Playbooks

by Mattermost

CVEs (7)

  • CVE-2023-45316HigDec 12, 2023
    risk 0.47cvss 7.3epss 0.00

    Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.

  • CVE-2023-27264HigFeb 27, 2023
    risk 0.46cvss 7.1epss 0.01

    A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.

  • CVE-2023-45847MedDec 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to send a specially crafted request and crash the Playbooks plugin

  • CVE-2022-4019MedNov 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

  • CVE-2022-1548LowMay 3, 2022
    risk 0.24cvss 3.7epss 0.01

    Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins.

  • CVE-2022-1333LowApr 13, 2022
    risk 0.23cvss 3.5epss 0.01

    Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of…

  • CVE-2026-4286LowMay 18, 2026
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing manage members restriction via PUT api.…