[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2017-18892":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-06T08:55:34.825Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":36,"aliases":37,"duplicate_of":9,"upstream":40,"downstream":41,"duplicates":44,"related":45,"reserved_at":9,"published_at":47,"modified_at":48,"state":49,"summary":50,"references_raw":59,"kevs":99,"epss":100,"epss_history":103,"metrics":360,"affected":373},"CVE-2017-18892","An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-116","Improper Encoding or Escaping of Output","The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.","weakness","Draft","Class","High",[20,24,28,32],{"id":21,"name":22,"techniques":23},"CAPEC-104","Cross Zone Scripting",[],{"id":25,"name":26,"techniques":27},"CAPEC-73","User-Controlled Filename",[],{"id":29,"name":30,"techniques":31},"CAPEC-81","Web Server Logs Tampering",[],{"id":33,"name":34,"techniques":35},"CAPEC-85","AJAX Footprinting",[],[],[38,39],"GHSA-wj5w-qghh-gvqp","GO-2026-4317",[],[42],{"_key":43},"SUSE-SU-2026:0292-1",[],[46],{"_key":43},"2020-06-19T18:08:51.000Z","2024-08-05T21:37:44.449Z","Modified",{"cisa_kev":51,"cisa_ransomware":51,"cisa_vendor":9,"epss_severity":52,"epss_score":53,"severity":54,"severity_score":55,"severity_version":56,"severity_source":57,"severity_vector":58,"severity_status":49},false,"low",0.00243,"medium",6.1,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",[60,67,73,78,82,86,91,95],{"url":61,"sources":62,"tags":64},"https://mattermost.com/security-updates/",[63,57],"cve.org",[65,66],"X Refsource CONFIRM","Vendor Advisory",{"url":68,"sources":69,"tags":71},"https://nvd.nist.gov/vuln/detail/CVE-2017-18892",[70],"osv_go",[72],"Advisory",{"url":74,"sources":75,"tags":76},"https://github.com/mattermost/mattermost/commit/4e05fbffed4d7ad75c0bb55d67d2c6f7cf9eaad6",[70],[77],"WEB",{"url":79,"sources":80,"tags":81},"https://github.com/mattermost/mattermost/commit/d76946bdb545aba4088943fc523dabb459d22873",[70],[77],{"url":83,"sources":84,"tags":85},"https://github.com/mattermost/mattermost/commit/f5167f3ba645b829f4c28530e13be6c3db967255",[70],[77],{"url":87,"sources":88,"tags":89},"https://github.com/mattermost/mattermost",[70],[90],"PACKAGE",{"url":92,"sources":93,"tags":94},"https://mattermost.com/security-updates",[70],[77],{"url":96,"sources":97,"tags":98},"https://github.com/advisories/GHSA-wj5w-qghh-gvqp",[70],[72],[],{"date":101,"score":53,"percentile":102},"2026-06-05",0.47804,[104,107,110,113,116,119,122,125,128,131,134,137,140,142,145,148,151,154,157,159,162,165,167,170,173,176,179,182,185,188,191,194,197,199,202,205,208,211,214,217,219,222,225,228,231,234,237,240,243,246,249,252,255,257,260,263,265,268,270,273,276,279,282,285,287,290,293,296,299,302,304,307,310,313,316,318,321,324,327,330,333,335,337,340,343,346,349,352,355,358],{"date":105,"score":53,"percentile":106},"2025-11-04",0.47461,{"date":108,"score":53,"percentile":109},"2025-11-05",0.47449,{"date":111,"score":53,"percentile":112},"2025-11-06",0.47464,{"date":114,"score":53,"percentile":115},"2025-11-07",0.47493,{"date":117,"score":53,"percentile":118},"2025-11-08",0.47492,{"date":120,"score":53,"percentile":121},"2025-11-09",0.47474,{"date":123,"score":53,"percentile":124},"2025-11-10",0.47447,{"date":126,"score":53,"percentile":127},"2025-11-11",0.47463,{"date":129,"score":53,"percentile":130},"2025-11-12",0.47494,{"date":132,"score":53,"percentile":133},"2025-11-13",0.475,{"date":135,"score":53,"percentile":136},"2025-11-14",0.47513,{"date":138,"score":53,"percentile":139},"2025-11-15",0.47508,{"date":141,"score":53,"percentile":115},"2025-11-16",{"date":143,"score":53,"percentile":144},"2025-11-17",0.47471,{"date":146,"score":53,"percentile":147},"2025-11-18",0.44072,{"date":149,"score":53,"percentile":150},"2025-11-19",0.44079,{"date":152,"score":53,"percentile":153},"2025-11-20",0.44087,{"date":155,"score":53,"percentile":156},"2025-11-21",0.47462,{"date":158,"score":53,"percentile":106},"2025-11-22",{"date":160,"score":53,"percentile":161},"2025-11-23",0.47435,{"date":163,"score":53,"percentile":164},"2025-11-24",0.47424,{"date":166,"score":53,"percentile":161},"2025-11-25",{"date":168,"score":53,"percentile":169},"2025-11-26",0.47437,{"date":171,"score":53,"percentile":172},"2025-11-27",0.47442,{"date":174,"score":53,"percentile":175},"2025-11-28",0.47411,{"date":177,"score":53,"percentile":178},"2025-11-29",0.47392,{"date":180,"score":53,"percentile":181},"2025-11-30",0.47381,{"date":183,"score":53,"percentile":184},"2025-12-01",0.47532,{"date":186,"score":53,"percentile":187},"2025-12-02",0.47545,{"date":189,"score":53,"percentile":190},"2025-12-03",0.47538,{"date":192,"score":53,"percentile":193},"2025-12-04",0.47374,{"date":195,"score":53,"percentile":196},"2025-12-05",0.47394,{"date":198,"score":53,"percentile":196},"2025-12-06",{"date":200,"score":53,"percentile":201},"2025-12-07",0.47382,{"date":203,"score":53,"percentile":204},"2025-12-08",0.47387,{"date":206,"score":53,"percentile":207},"2025-12-09",0.47418,{"date":209,"score":53,"percentile":210},"2025-12-10",0.47482,{"date":212,"score":53,"percentile":213},"2025-12-11",0.47504,{"date":215,"score":53,"percentile":216},"2025-12-12",0.4753,{"date":218,"score":53,"percentile":136},"2025-12-13",{"date":220,"score":53,"percentile":221},"2025-12-14",0.47501,{"date":223,"score":53,"percentile":224},"2025-12-15",0.47483,{"date":226,"score":53,"percentile":227},"2025-12-16",0.47495,{"date":229,"score":53,"percentile":230},"2025-12-17",0.4752,{"date":232,"score":53,"percentile":233},"2025-12-18",0.47562,{"date":235,"score":53,"percentile":236},"2025-12-19",0.47568,{"date":238,"score":53,"percentile":239},"2025-12-20",0.47546,{"date":241,"score":53,"percentile":242},"2025-12-21",0.47522,{"date":244,"score":53,"percentile":245},"2025-12-22",0.47499,{"date":247,"score":53,"percentile":248},"2025-12-23",0.47497,{"date":250,"score":53,"percentile":251},"2025-12-24",0.47511,{"date":253,"score":53,"percentile":254},"2025-12-25",0.47557,{"date":256,"score":53,"percentile":187},"2025-12-26",{"date":258,"score":53,"percentile":259},"2025-12-27",0.47573,{"date":261,"score":53,"percentile":262},"2025-12-28",0.47484,{"date":264,"score":53,"percentile":127},"2025-12-29",{"date":266,"score":53,"percentile":267},"2025-12-30",0.47457,{"date":269,"score":53,"percentile":221},"2025-12-31",{"date":271,"score":53,"percentile":272},"2026-01-01",0.47661,{"date":274,"score":53,"percentile":275},"2026-01-02",0.47639,{"date":277,"score":53,"percentile":278},"2026-01-03",0.47625,{"date":280,"score":53,"percentile":281},"2026-01-04",0.47448,{"date":283,"score":53,"percentile":284},"2026-01-05",0.47431,{"date":286,"score":53,"percentile":161},"2026-01-06",{"date":288,"score":53,"percentile":289},"2026-01-07",0.47451,{"date":291,"score":53,"percentile":292},"2026-01-08",0.47472,{"date":294,"score":53,"percentile":295},"2026-01-09",0.47444,{"date":297,"score":53,"percentile":298},"2026-01-10",0.47438,{"date":300,"score":53,"percentile":301},"2026-01-11",0.47416,{"date":303,"score":53,"percentile":193},"2026-01-12",{"date":305,"score":53,"percentile":306},"2026-01-13",0.47342,{"date":308,"score":53,"percentile":309},"2026-01-14",0.47388,{"date":311,"score":53,"percentile":312},"2026-01-15",0.4738,{"date":314,"score":53,"percentile":315},"2026-01-16",0.47403,{"date":317,"score":53,"percentile":201},"2026-01-17",{"date":319,"score":53,"percentile":320},"2026-01-18",0.47355,{"date":322,"score":53,"percentile":323},"2026-01-19",0.47328,{"date":325,"score":53,"percentile":326},"2026-01-20",0.47325,{"date":328,"score":53,"percentile":329},"2026-01-21",0.47327,{"date":331,"score":53,"percentile":332},"2026-01-22",0.4733,{"date":334,"score":53,"percentile":312},"2026-01-23",{"date":336,"score":53,"percentile":204},"2026-01-24",{"date":338,"score":53,"percentile":339},"2026-01-25",0.47334,{"date":341,"score":53,"percentile":342},"2026-01-26",0.47303,{"date":344,"score":53,"percentile":345},"2026-01-27",0.47308,{"date":347,"score":53,"percentile":348},"2026-01-28",0.47318,{"date":350,"score":53,"percentile":351},"2026-01-29",0.47307,{"date":353,"score":53,"percentile":354},"2026-01-30",0.47316,{"date":356,"score":53,"percentile":357},"2026-01-31",0.47323,{"date":359,"score":53,"percentile":156},"2026-02-01",[361,371],{"source":57,"cvss_v2_0":362,"cvss_v3_0":9,"cvss_v3_1":367,"cvss_v4_0":9},{"baseScore":363,"baseSeverity":9,"vectorString":364,"impactScore":365,"exploitabilityScore":366},4.3,"AV:N/AC:M/Au:N/C:N/I:P/A:N",2.9,8.6,{"baseScore":55,"baseSeverity":368,"vectorString":58,"impactScore":369,"exploitabilityScore":370},"MEDIUM",4.5,7.2,{"source":70,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":372,"cvss_v4_0":9},{"baseScore":55,"baseSeverity":9,"vectorString":58,"impactScore":369,"exploitabilityScore":370},[374,400],{"ecosystem":375,"name":376,"vendor":377,"product":378,"cpe_part":9,"purl_type":379,"purl_namespace":377,"purl_name":378,"source":9,"versions":380},"Go","github.com/mattermost/mattermost-server","github.com/mattermost","mattermost-server","golang",[381,389,392,396],{"version":382,"is_range":383,"range_type":384,"version_start":385,"version_start_type":386,"version_end":387,"version_end_type":388,"fixed_in":9},"gte4_2_0_rc1+incompatible_lt4_2_0+incompatible",true,"semver","4.2.0-rc1+incompatible","including","4.2.0+incompatible","excluding",{"version":390,"is_range":383,"range_type":384,"version_start":9,"version_start_type":9,"version_end":391,"version_end_type":388,"fixed_in":9},"lt4_0_5","4.0.5",{"version":393,"is_range":383,"range_type":384,"version_start":394,"version_start_type":386,"version_end":395,"version_end_type":388,"fixed_in":9},"gte4_1_0_lt4_1_1","4.1.0","4.1.1",{"version":397,"is_range":383,"range_type":384,"version_start":398,"version_start_type":386,"version_end":399,"version_end_type":388,"fixed_in":9},"gte4_2_0_rc1_lt4_2_0","4.2.0-rc1","4.2.0",{"ecosystem":9,"name":401,"vendor":402,"product":403,"cpe_part":404,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":405},"mattermost server","mattermost","mattermost_server","a",[406,409,411,413,415,417],{"version":407,"is_range":383,"range_type":408,"version_start":9,"version_start_type":9,"version_end":391,"version_end_type":388,"fixed_in":9},"lt4.0.5","cpe",{"version":410,"is_range":383,"range_type":408,"version_start":394,"version_start_type":386,"version_end":395,"version_end_type":388,"fixed_in":9},"gte4.1.0_lt4.1.1",{"version":412,"is_range":51,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"4.2.0:rc1",{"version":414,"is_range":51,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"4.2.0:rc2",{"version":416,"is_range":51,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"4.2.0:rc3",{"version":418,"is_range":51,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"4.2.0:rc4"]