cbcvebase.

Github.Com Mattermost Mattermost-Plugin-Calls vulnerabilities

3 known vulnerabilities affecting github.com/mattermost_mattermost-plugin-calls.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-6347P3HIGH≥ 0, < 1.12.0-rc22026-05-18
CVE-2026-6347 [HIGH] CWE-200 Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server credentials via the plaintext values present in the expo
ghsa
CVE-2025-12689P3MEDIUM≥ 0, < 1.11.02025-12-17
CVE-2025-12689 [MEDIUM] CWE-1287 Mattermost fails to check Websocket request for proper UTF-8 format potentially crashing Calls plug-in Mattermost fails to check Websocket request for proper UTF-8 format potentially crashing Calls plug-in Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.
ghsaosv
CVE-2025-62190P4MEDIUM≥ 0, < 1.10.02025-12-17
CVE-2025-62190 [MEDIUM] CWE-352 Mattermost has CSRF vulnerability via Calls Widget page Mattermost has CSRF vulnerability via Calls Widget page Mattermost versions 11.0.x < 11.0.4, 10.12.x <= 10.12.2, 10.11.x < 10.11.6 and Mattermost Calls versions < 1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link.
ghsaosv
Github.Com Mattermost Mattermost-Plugin-Calls vulnerabilities | cvebase