Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost Server HIGH 7.5
CVE-2026-24458

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to …

Fix: 10.11.11 / 11.2.3+
Fix from $1,950 2026-03-16
Mattermost Desktop MEDIUM 6.5
CVE-2026-1046

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary exec…

Fix: 5.13.3 / 6.0.3+
Fix from $1,600 2026-02-16
Mattermost Server MEDIUM 5.7
CVE-2025-13821

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authent…

Fix: 10.11.10 / 11.1.3+
Fix from $1,600 2026-02-16
Confluence MEDIUM 5.4
CVE-2025-13523

Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authentica…

Fix: 1.7.0+
Fix from $1,600 2026-02-06
Mattermost Server MEDIUM 6.5
CVE-2025-14435

Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticat…

Fix: 10.11.9 / 11.0.7+
Fix from $1,600 2026-01-16
Mattermost Server MEDIUM 6.5
CVE-2025-14822

Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU r…

Fix: 10.11.9+
Fix from $1,600 2026-01-16
Mattermost Server HIGH 8.3
CVE-2025-14273

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugi…

Fix: 10.11.8 / 10.12.4+
Fix from $1,950 2025-12-22
Mattermost Server MEDIUM 6.5
CVE-2025-12689

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which all…

Fix: 10.11.7 / 10.12.3+
Fix from $1,600 2025-12-17
Mattermost Server MEDIUM 6.1
CVE-2025-62690

Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a maliciou…

Fix: 10.11.5+
Fix from $1,600 2025-12-17
Mattermost Server CRITICAL 9.9
CVE-2025-12421

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code…

Fix: 10.5.13 / 10.11.5+
Fix from $2,300 2025-11-27
Mattermost Server CRITICAL 9.9
CVE-2025-12419

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during O…

Fix: 10.5.13 / 10.11.5+
Fix from $2,300 2025-11-27
Mattermost Server HIGH 7.5
CVE-2025-55070

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive i…

Fix: 11.0.0+
Fix from $1,950 2025-11-14
Mattermost Server MEDIUM 5.3
CVE-2025-55073

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and th…

Fix: 10.5.12 / 10.11.4+
Fix from $1,600 2025-11-14
Mattermost Mobile MEDIUM 6.5
CVE-2025-59480

Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermo…

Fix: 2.33.0+
Fix from $1,600 2025-11-13
Mattermost Desktop MEDIUM 6.1
CVE-2025-55035

Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authenti…

Fix: 5.13.1.0+
Fix from $1,600 2025-10-16
Mattermost Server HIGH 8.1
CVE-2025-58075

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using th…

Fix: 10.5.11 / 10.10.3+
Fix from $1,950 2025-10-16
Mattermost Server HIGH 8.1
CVE-2025-58073

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using th…

Fix: 10.5.11 / 10.10.3+
Fix from $1,950 2025-10-16
Mattermost Server MEDIUM 5.4
CVE-2025-41410

Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allo…

Fix: 10.5.11 / 10.10.3+
Fix from $1,600 2025-10-16
Mattermost Desktop MEDIUM 6.5
CVE-2025-58084

Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the u…

Fix: 5.13.1.0+
Fix from $1,600 2025-10-13
Mattermost Server HIGH 7.2
CVE-2025-9079

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory pat…

Fix: 9.11.18 / 10.5.9+
Fix from $1,950 2025-09-19
Mattermost Server MEDIUM 6.5
CVE-2025-9081

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sen…

Fix: 9.11.17 / 10.5.9+
Fix from $1,600 2025-09-19
Mattermost Server MEDIUM 6.1
CVE-2025-9084

Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted …

Fix: 10.5.10+
Fix from $1,600 2025-09-15
Mattermost Server MEDIUM 5.4
CVE-2025-9072

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft …

Fix: 10.5.10 / 10.9.5+
Fix from $1,600 2025-09-15
Mattermost Server MEDIUM 6.5
CVE-2025-9076

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious o…

Fix: 10.10.2+
Fix from $1,600 2025-09-15
Mattermost Server MEDIUM 6.8
CVE-2025-49222

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remo…

Fix: 9.11.18 / 10.5.9+
Fix from $1,600 2025-08-21
Confluence HIGH 7.5
CVE-2025-54463

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to se…

Fix: 1.5.0+
Fix from $1,950 2025-08-11
Confluence HIGH 7.5
CVE-2025-54525

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to cr…

Fix: 1.5.0+
Fix from $1,950 2025-08-11
Confluence MEDIUM 5.3
CVE-2025-54478

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attac…

Fix: 1.5.0+
Fix from $1,600 2025-08-11
Confluence MEDIUM 5.3
CVE-2025-8285

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscriptio…

Fix: 1.5.0+
Fix from $1,600 2025-08-11
Confluence MEDIUM 5.9
CVE-2025-53514

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to se…

Fix: 1.5.0+
Fix from $1,600 2025-08-11