Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost MEDIUM 6.5
CVE-2021-37864

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view conte…

Fix: after 6.1
Fix from $1,600 2022-01-18
Mattermost MEDIUM 5.7
CVE-2021-37865

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows auth…

Fix: after 6.2.0
Fix from $1,600 2022-01-18
Mattermost Server MEDIUM 5.7
CVE-2021-37863

Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-sid…

Fix: after 6.0
Fix from $1,600 2021-12-17
Mattermost Server MEDIUM 5.4
CVE-2021-37862

Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing u…

Fix: after 6.0
Fix from $1,600 2021-12-17
Mattermost HIGH 7.5
CVE-2021-37861

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

Fix: after 6.0.2
Fix from $1,950 2021-12-09
Mattermost MEDIUM 6.1
CVE-2021-37860

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script i…

Fix: after 5.38
Fix from $1,600 2021-09-22
Mattermost MEDIUM 6.1
CVE-2021-37859

Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.

Fix: 5.34.5 / 5.35.4+
Fix from $1,600 2021-08-05
Mattermost HIGH 7.5
CVE-2020-13891

An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, a…

Fix: 1.31.2+
Fix from $1,950 2020-06-26
Mattermost Server CRITICAL 9.8
CVE-2017-18908

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-ma…

Fix: 3.9.2 / 3.10.2+
Fix from $2,300 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2017-18915

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoin…

Fix: 3.6.7 / 3.7.5+
Fix from $2,300 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2017-18920

An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.

Fix: 3.6.2+
Fix from $2,300 2020-06-19
Mattermost Server HIGH 8.1
CVE-2017-18906

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody el…

Fix: 3.9.2 / 3.10.2+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2017-18917

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verifica…

Fix: 3.6.7 / 3.7.5+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2016-11084

An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.

Fix: 2.1.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18907

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.

Fix: 3.9.2 / 3.10.2+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18913

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.

Fix: 3.6.7 / 3.7.5+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18921

An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.

Fix: 3.5.2+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18905

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mi…

Fix: 3.9.2 / 3.10.2+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18914

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allo…

Fix: 3.6.7 / 3.7.5+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18916

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission res…

Fix: 3.6.7 / 3.7.5+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18919

An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.

Fix: 3.6.3+
Fix from $1,600 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2016-11074

An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.

Fix: 3.0.0+
Fix from $2,300 2020-06-19
Mattermost Server HIGH 7.5
CVE-2016-11069

An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.

Fix: 3.2.0+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.5
CVE-2016-11072

An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.

Fix: 3.0.2+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.5
CVE-2016-11078

An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within …

Fix: 3.0.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2016-11071

An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.

Fix: 3.1.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2016-11073

An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.

Fix: 3.0.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2016-11079

An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.

Fix: 3.0.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2016-11082

An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.

Fix: 2.2.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2016-11083

An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.

Fix: 2.2.0+
Fix from $1,600 2020-06-19