Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-10080 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authentic… Mattermost Server Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.3 CVE-2026-16048 Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles w… Mattermost Server Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.3 CVE-2026-10527 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which all… Mattermost Server Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.4 CVE-2026-16044 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive impo… Mattermost Server Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.5 CVE-2026-14298 Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when proces… Mattermost Server No fix yet Fix from $4,0002026-08-13 MEDIUM 5.5 CVE-2026-7521 Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin… Mattermost Server 10.11.21 / 11.6.6+ Fix from $1,6002026-07-28 MEDIUM 6.5 CVE-2026-10819 Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file… Mattermost Server 10.11.21 / 11.6.6+ Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-8075 Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows… Mattermost Desktop 5.13.6 / 6.2.1+ Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-9602 Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a mal… Mattermost Desktop 5.13.7 / 6.2.1+ Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-9571 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, w… Mattermost Server 10.11.20 / 11.6.5+ Fix from $1,6002026-07-13 MEDIUM 5.4 CVE-2026-9597 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-l… Mattermost Server 11.6.5 / 11.7.3+ Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-6850 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field value… Mattermost Server 10.11.20 / 11.6.5+ Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-10106 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches th… Mattermost Server 10.11.20 / 11.6.5+ Fix from $1,6002026-07-13 MEDIUM 5.4 CVE-2026-10085 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private… Mattermost Server 10.11.20 / 11.6.5+ Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-4339 Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in… Mattermost Server 10.11.19 / 11.5.7+ Fix from $1,6002026-06-26 MEDIUM 6.4 CVE-2026-6062 Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subsc… Mattermost Server 10.11.18 / 11.5.6+ Fix from $1,6002026-06-22 MEDIUM 6.4 CVE-2026-6673 Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callba… Mattermost Server 10.11.18 / 11.5.6+ Fix from $1,6002026-06-22 MEDIUM 5.4 CVE-2026-5139 Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{se… Mattermost Server 10.11.18 / 11.5.6+ Fix from $1,6002026-06-22 MEDIUM 6.5 CVE-2026-8683 Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows … Mattermost Desktop after 6.1.5 Fix from $1,6002026-06-15 HIGH 7.7 CVE-2026-6517 Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermo… Mattermost Desktop after 6.1.5 Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-7387 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authoriz… Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,9502026-06-12 HIGH 7.6 CVE-2026-6961 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received … Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,9502026-06-12 HIGH 7.2 CVE-2026-6739 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patchin… Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,9502026-06-12 MEDIUM 6.5 CVE-2026-7184 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, whi… Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-6046 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot… Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,6002026-06-12 MEDIUM 6.5 CVE-2026-4915 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attac… Mattermost Server 10.11.15 / 11.4.5+ Fix from $1,6002026-05-25 MEDIUM 5.4 CVE-2026-28735 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback … Mattermost Server 10.11.15 / 11.4.5+ Fix from $1,6002026-05-22 HIGH 7.5 CVE-2026-5308 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP… Mattermost Server 10.11.15 / 11.4.5+ Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-5740 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket fra… Mattermost Server 10.11.15 / 11.4.5+ Fix from $1,9502026-05-22 MEDIUM 6.5 CVE-2026-5755 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset … Mattermost Server 10.11.15 / 11.4.5+ Fix from $1,6002026-05-22