Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost Server HIGH 7.1
CVE-2026-3473

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, whi…

Fix: 10.11.15 / 11.4.5+
Fix from $1,950 2026-05-22
Mattermost Server MEDIUM 5.3
CVE-2026-4635

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent …

Fix: 10.11.15 / 11.4.5+
Fix from $1,600 2026-05-22
Mattermost Server CRITICAL 9.9
CVE-2026-4858

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which …

Fix: 10.11.15 / 11.4.5+
Fix from $2,300 2026-05-21
Mattermost Mobile MEDIUM 6.1
CVE-2026-22880

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin w…

Fix: 2.37.1+
Fix from $1,600 2026-05-21
Mattermost Server HIGH 8.7
CVE-2026-6346

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in …

Fix: 10.11.14 / 11.4.4+
Fix from $1,950 2026-05-18
Mattermost Server HIGH 7.6
CVE-2026-6347

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls p…

Fix: 10.11.14 / 11.4.4+
Fix from $1,950 2026-05-18
Mattermost Server MEDIUM 6.5
CVE-2026-5163

Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated att…

Fix: 11.5.2+
Fix from $1,600 2026-05-18
Mattermost Server MEDIUM 6.5
CVE-2026-6345

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious…

Fix: 10.11.14 / 11.4.4+
Fix from $1,600 2026-05-18
Mattermost Server MEDIUM 5.0
CVE-2026-6333

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands …

Fix: 10.11.14 / 11.5.2+
Fix from $1,600 2026-05-18
Mattermost Server MEDIUM 6.5
CVE-2026-3117

Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin whic…

Fix: after 11.3.4
Fix from $1,600 2026-05-18
Mattermost Desktop MEDIUM 6.5
CVE-2026-3471

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App whi…

Fix: 6.2.0+
Fix from $1,600 2026-05-18
Mattermost Server MEDIUM 6.5
CVE-2026-6340

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an…

Fix: 10.11.14 / 11.4.4+
Fix from $1,600 2026-05-18
Mattermost Server MEDIUM 6.5
CVE-2026-2325

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpo…

Fix: 10.11.14 / 11.4.4+
Fix from $1,600 2026-05-18
Mattermost Server MEDIUM 6.5
CVE-2026-4054

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remo…

Fix: 10.11.14 / 11.4.4+
Fix from $1,600 2026-05-15
Mattermost Server MEDIUM 6.5
CVE-2026-3590

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest …

Fix: 10.11.13 / 11.3.3+
Fix from $1,600 2026-04-15
Mattermost Server HIGH 8.1
CVE-2026-28741

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpo…

Fix: 10.11.13 / 11.3.3+
Fix from $1,950 2026-04-15
Mattermost MEDIUM 6.5
CVE-2026-24661

Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker…

Fix: 2.3.2.0+
Fix from $1,600 2026-04-09
Mattermost Server MEDIUM 6.5
CVE-2026-21388

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker…

Fix: after 2.3.1
Fix from $1,600 2026-04-09
Legal Hold HIGH 8.8
CVE-2026-3524

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authent…

Fix: 1.1.5+
Fix from $1,950 2026-04-06
Focalboard MEDIUM 6.5
CVE-2026-25773

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dynamic SQL statements when reor…

Mitigation only
Fix from $1,600 2026-04-03
Mattermost Server MEDIUM 6.5
CVE-2026-3114

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes durin…

Fix: 10.11.12 / 11.2.4+
Fix from $1,600 2026-03-26
Mattermost Server MEDIUM 5.5
CVE-2026-3113

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which…

Fix: 10.11.12 / 11.2.4+
Fix from $1,600 2026-03-26
Mattermost Server HIGH 8.8
CVE-2026-3108

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mm…

Fix: 10.11.11 / 11.2.3+
Fix from $1,950 2026-03-26
Mattermost Server MEDIUM 5.4
CVE-2026-4274

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing memb…

Fix: 10.11.11 / 11.2.3+
Fix from $1,600 2026-03-26
Mattermost Server MEDIUM 6.1
CVE-2026-27656

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {…

Fix: 10.11.12 / 11.2.4+
Fix from $1,600 2026-03-25
Mattermost Server MEDIUM 6.5
CVE-2026-26233

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login requests which allows unauthen…

Fix: 10.11.12 / 11.2.4+
Fix from $1,600 2026-03-25
Mattermost Server HIGH 7.5
CVE-2026-20719

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embe…

Fix: 10.11.12 / 11.2.4+
Fix from $1,950 2026-03-25
Mattermost Server HIGH 8.6
CVE-2026-2454

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious …

Fix: 10.11.11 / 11.2.3+
Fix from $1,950 2026-03-16
Mattermost Server MEDIUM 6.6
CVE-2026-2462

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default ad…

Fix: 10.11.11 / 11.2.3+
Fix from $1,600 2026-03-16
Mattermost Server MEDIUM 5.7
CVE-2026-2456

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action e…

Fix: 10.11.11 / 11.2.3+
Fix from $1,600 2026-03-16