Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost MEDIUM 5.3
CVE-2023-48369

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially o…

Fix: after 9.0.1
Fix from $1,600 2023-11-27
Mattermost HIGH 7.5
CVE-2023-40703

Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessiv…

Fix: after 9.0.1
Fix from $1,950 2023-11-27
Mattermost MEDIUM 5.4
CVE-2023-35075

Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML…

Fix: after 8.1.3
Fix from $1,600 2023-11-27
Mattermost MEDIUM 5.3
CVE-2023-5969

Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/r…

Fix: after 8.1.2
Fix from $1,600 2023-11-06
Mattermost Desktop MEDIUM 5.3
CVE-2023-5875

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a …

Fix: 5.5.1+
Fix from $1,600 2023-11-02
Mattermost Desktop MEDIUM 5.3
CVE-2023-5876

Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial…

Fix: 5.5.1+
Fix from $1,600 2023-11-02
Mattermost Desktop MEDIUM 5.5
CVE-2023-5339

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including pa…

Fix: after 5.4.0
Fix from $1,600 2023-10-17
Mattermost Server HIGH 7.5
CVE-2023-5330

Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to t…

Fix: 7.8.11 / 8.0.3+
Fix from $1,950 2023-10-09
Mattermost Server MEDIUM 6.5
CVE-2023-5333

Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sendin…

Fix: 7.8.11 / 8.0.3+
Fix from $1,600 2023-10-09
Mattermost Server MEDIUM 5.3
CVE-2023-5331

Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file infor…

Fix: 7.8.11 / 8.0.3+
Fix from $1,600 2023-10-09
Mattermost MEDIUM 6.5
CVE-2023-5196

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_p…

Fix: 7.8.10 / 8.0.2+
Fix from $1,600 2023-09-29
Mattermost MEDIUM 5.4
CVE-2023-5195

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not p…

Fix: 7.8.10 / 8.0.2+
Fix from $1,600 2023-09-29
Mattermost Server HIGH 8.2
CVE-2023-4478

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thu…

Fix: 7.8.9 / 7.10.5+
Fix from $1,950 2023-08-25
Mattermost HIGH 7.5
CVE-2023-4108

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

Fix: 7.8.8 / 7.9.6+
Fix from $1,950 2023-08-11
Mattermost MEDIUM 6.5
CVE-2023-4106

Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to …

Fix: 7.8.8 / 7.9.6+
Fix from $1,600 2023-08-11
Mattermost MEDIUM 6.5
CVE-2023-4107

Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin'…

Fix: 7.8.8 / 7.9.6+
Fix from $1,600 2023-08-11
Mattermost HIGH 8.1
CVE-2023-3615

Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept t…

Fix: 2.5.1+
Fix from $1,950 2023-07-17
Mattermost Server MEDIUM 6.5
CVE-2023-3593

Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.

Fix: 7.8.7 / 7.9.5+
Fix from $1,600 2023-07-17
Mattermost Server HIGH 8.2
CVE-2023-3591

Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.

Fix: 7.8.7 / 7.9.5+
Fix from $1,950 2023-07-17
Mattermost Server HIGH 8.1
CVE-2023-3581

Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.

Fix: 7.8.7 / 7.9.5+
Fix from $1,950 2023-07-17
Mattermost Server HIGH 7.5
CVE-2023-3590

Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.

Fix: 7.10.3+
Fix from $1,950 2023-07-17
Mattermost Server MEDIUM 5.4
CVE-2023-3586

Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared …

Fix: 7.8.7 / 7.9.5+
Fix from $1,600 2023-07-17
Mattermost MEDIUM 6.5
CVE-2023-2792

Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg com…

Fix: after 7.9.3
Fix from $1,600 2023-06-16
Mattermost MEDIUM 6.5
CVE-2023-2793

Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-s…

Fix: after 7.9.2
Fix from $1,600 2023-06-16
Mattermost MEDIUM 6.5
CVE-2023-2797

Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink…

Fix: after 7.8.4
Fix from $1,600 2023-06-16
Mattermost MEDIUM 6.5
CVE-2023-2831

Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message conta…

Fix: after 7.9.3
Fix from $1,600 2023-06-16
Mattermost MEDIUM 6.5
CVE-2023-2784

Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install…

Fix: after 7.9.3
Fix from $1,600 2023-06-16
Mattermost MEDIUM 6.5
CVE-2023-2787

Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message thre…

Fix: after 7.9.3
Fix from $1,600 2023-06-16
Mattermost MEDIUM 6.5
CVE-2023-2788

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persi…

Fix: after 7.9.3
Fix from $1,600 2023-06-16
Mattermost MEDIUM 5.3
CVE-2023-2808

Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to tr…

Fix: 7.1.9 / 7.8.4+
Fix from $1,600 2023-05-29