Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost Server MEDIUM 5.4
CVE-2016-11070

An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.

Fix: 3.1.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2016-11075

An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.

Fix: 3.0.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2016-11076

An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.

Fix: 3.0.0+
Fix from $1,600 2020-06-19
Mattermost Desktop CRITICAL 9.8
CVE-2016-11064

An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.

Fix: 3.4.0+
Fix from $2,300 2020-06-19
Mattermost Server HIGH 7.5
CVE-2015-9548

An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compress…

Fix: 1.2.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2016-11066

An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.

Fix: 3.2.0+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2016-11063

An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.

Fix: 3.5.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2016-11062

An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.

Fix: 3.5.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2016-11067

An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.

Fix: 3.2.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2016-11068

An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.

Fix: 3.2.0+
Fix from $1,600 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2017-18900

An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.

Fix: 3.10.3 / 4.0.4+
Fix from $2,300 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2017-18912

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.

Fix: 3.6.7 / 3.7.5+
Fix from $2,300 2020-06-19
Mattermost Server CRITICAL 9.1
CVE-2017-18911

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail s…

Fix: 3.6.7 / 3.7.5+
Fix from $2,300 2020-06-19
Mattermost Server HIGH 8.8
CVE-2017-18903

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.

Fix: 3.9.2 / 3.10.2+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2017-18909

An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.

Fix: 3.9.0+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18897

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action …

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18904

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.

Fix: 3.9.2 / 3.10.2+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18895

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via …

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18896

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API versio…

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18898

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang.

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18899

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18901

An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON d…

Fix: 3.10.3 / 4.0.4+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18902

An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.

Fix: 3.10.3 / 4.0.4+
Fix from $1,600 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2017-18885

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpo…

Fix: 4.1.2 / 4.2.1+
Fix from $2,300 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2017-18888

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.

Fix: 4.1.2 / 4.2.1+
Fix from $2,300 2020-06-19
Mattermost Server CRITICAL 9.1
CVE-2017-18883

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for …

Fix: 4.1.2 / 4.2.1+
Fix from $2,300 2020-06-19
Mattermost Server HIGH 8.8
CVE-2017-18886

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.

Fix: 4.1.2 / 4.2.1+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 8.1
CVE-2017-18884

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth appli…

Fix: 4.1.2 / 4.2.1+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 8.1
CVE-2017-18894

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner au…

Fix: 4.0.5 / 4.1.1+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18879

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19