Package impact

golang GO / github.com/mattermost/mattermost/server/v8

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-28741 medium 5.5 1mo ago Mattermost doesn't validate CSRF tokens on an authentication endpoint
CVE-2026-3590 medium 5.5 1mo ago Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement