Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Confluence MEDIUM 5.0
CVE-2025-54458

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscrip…

Fix: 1.5.0+
Fix from $1,600 2025-08-11
Confluence HIGH 7.5
CVE-2025-52931

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to up…

Fix: 1.5.0+
Fix from $1,950 2025-08-11
Confluence HIGH 7.2
CVE-2025-44004

Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create …

Fix: 1.5.0+
Fix from $1,950 2025-08-11
Confluence MEDIUM 6.4
CVE-2025-48731

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscripti…

Fix: 1.5.0+
Fix from $1,600 2025-08-11
Mattermost Server MEDIUM 6.5
CVE-2025-6226

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts…

Fix: 9.11.17 / 10.5.7+
Fix from $1,600 2025-07-18
Mattermost Server MEDIUM 5.4
CVE-2025-46702

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member…

Fix: 9.11.16 / 10.5.6+
Fix from $1,600 2025-06-30
Mattermost Server MEDIUM 5.4
CVE-2025-47871

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membe…

Fix: 9.11.16 / 10.5.6+
Fix from $1,600 2025-06-30
Mattermost Server CRITICAL 9.9
CVE-2025-4981

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archi…

Fix: 9.11.16 / 10.5.6+
Fix from $2,300 2025-06-20
Mattermost Server MEDIUM 5.4
CVE-2025-3230

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon …

Fix: 9.11.13 / 10.5.4+
Fix from $1,600 2025-05-30
Mattermost Server MEDIUM 5.3
CVE-2025-31947

Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failu…

Fix: 9.11.12 / 10.4.5+
Fix from $1,600 2025-05-15
Mattermost Server HIGH 7.5
CVE-2025-35965

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the Upd…

Fix: 9.11.11 / 10.4.3+
Fix from $1,950 2025-04-24
Mattermost Server HIGH 7.5
CVE-2025-41395

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom po…

Fix: 9.11.11 / 10.4.3+
Fix from $1,950 2025-04-24
Mattermost Server MEDIUM 6.5
CVE-2025-31363

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allow…

Fix: 9.11.10 / 10.4.3+
Fix from $1,600 2025-04-16
Mattermost Server MEDIUM 5.9
CVE-2025-27936

Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant ti…

Fix: 2.1.0 / 10.5.2+
Fix from $1,600 2025-04-16
Mattermost Server MEDIUM 5.4
CVE-2025-2475

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which…

Fix: 9.11.10 / 10.4.4+
Fix from $1,600 2025-04-14
Mattermost Mobile HIGH 7.5
CVE-2025-30516

Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauth…

Fix: 2.26.0+
Fix from $1,950 2025-04-14
Mattermost Mobile MEDIUM 6.5
CVE-2025-1558

Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android a…

Fix: 2.25.1+
Fix from $1,600 2025-03-24
Mattermost Server MEDIUM 6.5
CVE-2025-30179

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attac…

Fix: 9.11.9 / 10.3.4+
Fix from $1,600 2025-03-21
Mattermost Server HIGH 8.8
CVE-2025-25068

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows auth…

Fix: 9.11.9 / 10.3.4+
Fix from $1,950 2025-03-21
Mattermost Server HIGH 8.8
CVE-2025-25274

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authen…

Fix: 9.11.9 / 10.3.4+
Fix from $1,950 2025-03-21
Mattermost Server HIGH 7.5
CVE-2025-25279EPSS 24%

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boar…

Fix: 9.11.8 / 10.2.3+
Fix from $1,950 2025-02-24
Mattermost Server MEDIUM 6.5
CVE-2025-20051

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicat…

Fix: 9.11.8 / 10.2.3+
Fix from $1,600 2025-02-24
Mattermost Server MEDIUM 6.5
CVE-2025-24490

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards…

Fix: 9.11.8 / 10.2.3+
Fix from $1,600 2025-02-24
Mattermost Server HIGH 8.8
CVE-2025-1412

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the conver…

Fix: 9.11.7 / 10.4.2+
Fix from $1,950 2025-02-24
Mattermost Server MEDIUM 5.3
CVE-2025-0503

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other m…

Fix: 9.11.7+
Fix from $1,600 2025-02-14
Mattermost Mobile HIGH 7.5
CVE-2025-20630

Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an…

Fix: 2.23.0+
Fix from $1,950 2025-01-16
Mattermost Server HIGH 7.5
CVE-2025-20621

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing …

Fix: 9.11.6 / 10.0.4+
Fix from $1,950 2025-01-16
Mattermost Mobile HIGH 7.5
CVE-2025-20072

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allo…

Fix: 2.23.0+
Fix from $1,950 2025-01-16
Mattermost Server MEDIUM 6.5
CVE-2025-20086

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malici…

Fix: 9.11.6 / 10.0.4+
Fix from $1,600 2025-01-15
Mattermost Server MEDIUM 6.5
CVE-2025-20088

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malici…

Fix: 9.11.6 / 10.0.4+
Fix from $1,600 2025-01-15