Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost Mobile MEDIUM 6.5
CVE-2025-21083

Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a mali…

Fix: 2.23.0+
Fix from $1,600 2025-01-15
Mattermost Mobile MEDIUM 6.5
CVE-2025-20036

Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a mali…

Fix: 2.23.0+
Fix from $1,600 2025-01-15
Mattermost Server MEDIUM 6.5
CVE-2025-21088

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to a…

Fix: 9.11.6 / 10.0.4+
Fix from $1,600 2025-01-15
Mattermost Server MEDIUM 6.5
CVE-2025-20033

Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny…

Fix: 9.11.6 / 10.0.4+
Fix from $1,600 2025-01-09
Mattermost Server MEDIUM 5.3
CVE-2025-22445

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive …

Fix: 10.3.0+
Fix from $1,600 2025-01-09
Mattermost Mobile MEDIUM 5.5
CVE-2024-11358

Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files…

Fix: 2.22.2+
Fix from $1,600 2024-12-16
Mattermost Server MEDIUM 6.5
CVE-2024-54083

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allow…

Fix: 9.5.13 / 9.11.5+
Fix from $1,600 2024-12-16
Mattermost Server MEDIUM 5.3
CVE-2024-11599

Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an u…

Fix: 9.5.12 / 9.11.4+
Fix from $1,600 2024-11-28
Mattermost Server HIGH 7.5
CVE-2024-47401

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks w…

Fix: 9.5.10 / 9.10.3+
Fix from $1,950 2024-10-29
Mattermost Server MEDIUM 6.5
CVE-2024-47003

Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker…

Fix: 9.5.9+
Fix from $1,600 2024-09-26
Mattermost Server MEDIUM 5.4
CVE-2024-45843

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker …

Fix: 9.5.9+
Fix from $1,600 2024-09-26
Mattermost Server MEDIUM 5.4
CVE-2024-42406

Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived c…

Fix: 9.5.9 / 9.9.3+
Fix from $1,600 2024-09-26
Mattermost Desktop MEDIUM 6.5
CVE-2024-45835

Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse ot…

Fix: 5.9.0+
Fix from $1,600 2024-09-16
Mattermost Desktop MEDIUM 5.3
CVE-2024-39772

Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality scre…

Fix: 5.9.0+
Fix from $1,600 2024-09-16
Mattermost Mobile MEDIUM 6.5
CVE-2024-45833

Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which …

Fix: 2.19.0+
Fix from $1,600 2024-09-16
Mattermost Desktop HIGH 7.8
CVE-2024-39613

Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able …

Fix: 5.9.0+
Fix from $1,950 2024-09-16
Mattermost HIGH 8.8
CVE-2024-40886

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for r…

Fix: 9.5.8 / 9.8.3+
Fix from $1,950 2024-08-22
Mattermost HIGH 7.2
CVE-2024-8071

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system adm…

Fix: 9.5.8 / 9.8.3+
Fix from $1,950 2024-08-22
Mattermost MEDIUM 5.3
CVE-2024-42411

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a …

Fix: 9.5.8 / 9.8.3+
Fix from $1,600 2024-08-22
Mattermost MEDIUM 6.5
CVE-2024-39836

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create ses…

Fix: 9.5.8 / 9.8.3+
Fix from $1,600 2024-08-22
Mattermost Server HIGH 7.1
CVE-2024-41144

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are e…

Fix: 9.5.7 / 9.7.6+
Fix from $1,950 2024-08-01
Mattermost CRITICAL 9.6
CVE-2024-39777

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local …

Fix: 9.5.7 / 9.7.6+
Fix from $2,300 2024-08-01
Mattermost HIGH 8.7
CVE-2024-39832

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malici…

Fix: 9.5.7 / 9.7.6+
Fix from $1,950 2024-08-01
Mattermost MEDIUM 6.5
CVE-2024-39274

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the …

Fix: 9.5.7 / 9.7.6+
Fix from $1,600 2024-08-01
Mattermost Server MEDIUM 5.4
CVE-2024-39837

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary cha…

Fix: 9.5.7+
Fix from $1,600 2024-08-01
Mattermost MEDIUM 6.4
CVE-2024-36492

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing user…

Fix: 9.5.7 / 9.7.6+
Fix from $1,600 2024-08-01
Mattermost Mobile MEDIUM 6.5
CVE-2024-39767

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which …

Fix: 2.17.0+
Fix from $1,600 2024-07-15
Mattermost Mobile MEDIUM 5.3
CVE-2024-32945

Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the cont…

Fix: 2.17.0+
Fix from $1,600 2024-07-15
Mattermost MEDIUM 6.5
CVE-2024-6428

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows…

Fix: 9.5.6 / 9.6.3+
Fix from $1,600 2024-07-03
Mattermost MEDIUM 5.9
CVE-2024-39830

Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time co…

Fix: 9.5.6 / 9.6.3+
Fix from $1,600 2024-07-03