Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2016-11082
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
Mattermost Server
2.2.0+
MEDIUM 6.1
CVE-2016-11083
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
Mattermost Server
2.2.0+
MEDIUM 5.4
CVE-2016-11070
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
Mattermost Server
3.1.0+
MEDIUM 5.3
CVE-2016-11075
An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
Mattermost Server
3.0.0+
MEDIUM 5.3
CVE-2016-11076
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
Mattermost Server
3.0.0+
CRITICAL 9.8
CVE-2016-11064
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
Mattermost Desktop
3.4.0+
HIGH 7.5
CVE-2015-9548
An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compress…
Mattermost Server
1.2.0+
HIGH 7.5
CVE-2016-11066
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
Mattermost Server
3.2.0+
MEDIUM 6.1
CVE-2016-11063
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
Mattermost Server
3.5.1+
MEDIUM 5.3
CVE-2016-11062
An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
Mattermost Server
3.5.1+
MEDIUM 5.3
CVE-2016-11067
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
Mattermost Server
3.2.0+
MEDIUM 5.3
CVE-2016-11068
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
Mattermost Server
3.2.0+
CRITICAL 9.8
CVE-2017-18900
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.
Mattermost Server
3.10.3 / 4.0.4+
CRITICAL 9.8
CVE-2017-18912
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.
Mattermost Server
3.6.7 / 3.7.5+
CRITICAL 9.1
CVE-2017-18911
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail s…
Mattermost Server
3.6.7 / 3.7.5+
HIGH 8.8
CVE-2017-18903
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
Mattermost Server
3.9.2 / 3.10.2+
HIGH 7.5
CVE-2017-18909
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
Mattermost Server
3.9.0+
MEDIUM 6.1
CVE-2017-18897
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action …
Mattermost Server
4.0.5 / 4.1.1+
MEDIUM 6.1
CVE-2017-18904
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.
Mattermost Server
3.9.2 / 3.10.2+
MEDIUM 5.3
CVE-2017-18895
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via …
Mattermost Server
4.0.5 / 4.1.1+
MEDIUM 5.3
CVE-2017-18896
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API versio…
Mattermost Server
4.0.5 / 4.1.1+
MEDIUM 5.3
CVE-2017-18898
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang.
Mattermost Server
4.0.5 / 4.1.1+
MEDIUM 5.3
CVE-2017-18899
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
Mattermost Server
4.0.5 / 4.1.1+
MEDIUM 5.3
CVE-2017-18901
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON d…
Mattermost Server
3.10.3 / 4.0.4+
MEDIUM 5.3
CVE-2017-18902
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.
Mattermost Server
3.10.3 / 4.0.4+
CRITICAL 9.8
CVE-2017-18885
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpo…
Mattermost Server
4.1.2 / 4.2.1+
CRITICAL 9.8
CVE-2017-18888
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
Mattermost Server
4.1.2 / 4.2.1+
CRITICAL 9.1
CVE-2017-18883
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for …
Mattermost Server
4.1.2 / 4.2.1+
HIGH 8.8
CVE-2017-18886
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
Mattermost Server
4.1.2 / 4.2.1+
HIGH 8.1
CVE-2017-18884
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth appli…
Mattermost Server
4.1.2 / 4.2.1+