← All credits
daw10
30 vulnerability records and advisories credit this contributor.
CVE-2026-28759
Insufficient authorization in shared channel membership sync allows remote cluster to remove users from arbitrary channels
CVE-2026-27769
Connected Workspaces: Malicious remote server can manipulate arbitrary user's status
CVE-2026-22545
Password Change Bypass via Auth Switch Endpoint
CVE-2026-0999
Authentication bypass via userID login when email and username login are disabled
CVE-2026-0998
Mattermost Zoom Plugin allows unauthorized meeting creation and post modification via insufficient API access controls
CVE-2026-0997
Mattermost Zoom Plugin channel preference API lacks authorization checks
CVE-2025-9081
IDOR in board file download allows any user to download any file by UUID
CVE-2025-9079
Admin RCE via prepackaged plugins by way of misconfigured imports directory
CVE-2025-9078
Weak cache keys lead to post IDOR and link preview poisoning
CVE-2025-9076
Mattermost Server exposes sensitive user credentials during shared channel membership synchronization