Vulnerability index

Browse CVEs

381 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2016-11082 An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link. Mattermost Server 2.2.0+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2016-11083 An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window. Mattermost Server 2.2.0+ Fix from $1,6002020-06-19 MEDIUM 5.4 CVE-2016-11070 An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values. Mattermost Server 3.1.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2016-11075 An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API. Mattermost Server 3.0.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2016-11076 An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL. Mattermost Server 3.0.0+ Fix from $1,6002020-06-19 CRITICAL 9.8 CVE-2016-11064 An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection. Mattermost Desktop 3.4.0+ Fix from $2,3002020-06-19 HIGH 7.5 CVE-2015-9548 An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compress… Mattermost Server 1.2.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2016-11066 An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information. Mattermost Server 3.2.0+ Fix from $1,9502020-06-19 MEDIUM 6.1 CVE-2016-11063 An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview. Mattermost Server 3.5.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2016-11062 An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed. Mattermost Server 3.5.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2016-11067 An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang. Mattermost Server 3.2.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2016-11068 An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection. Mattermost Server 3.2.0+ Fix from $1,6002020-06-19 CRITICAL 9.8 CVE-2017-18900 An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report. Mattermost Server 3.10.3 / 4.0.4+ Fix from $2,3002020-06-19 CRITICAL 9.8 CVE-2017-18912 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file. Mattermost Server 3.6.7 / 3.7.5+ Fix from $2,3002020-06-19 CRITICAL 9.1 CVE-2017-18911 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail s… Mattermost Server 3.6.7 / 3.7.5+ Fix from $2,3002020-06-19 HIGH 8.8 CVE-2017-18903 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled. Mattermost Server 3.9.2 / 3.10.2+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2017-18909 An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory. Mattermost Server 3.9.0+ Fix from $1,9502020-06-19 MEDIUM 6.1 CVE-2017-18897 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action … Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18904 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file. Mattermost Server 3.9.2 / 3.10.2+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18895 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via … Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18896 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API versio… Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18898 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang. Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18899 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting. Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18901 An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON d… Mattermost Server 3.10.3 / 4.0.4+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18902 An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints. Mattermost Server 3.10.3 / 4.0.4+ Fix from $1,6002020-06-19 CRITICAL 9.8 CVE-2017-18885 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpo… Mattermost Server 4.1.2 / 4.2.1+ Fix from $2,3002020-06-19 CRITICAL 9.8 CVE-2017-18888 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts. Mattermost Server 4.1.2 / 4.2.1+ Fix from $2,3002020-06-19 CRITICAL 9.1 CVE-2017-18883 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for … Mattermost Server 4.1.2 / 4.2.1+ Fix from $2,3002020-06-19 HIGH 8.8 CVE-2017-18886 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands. Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,9502020-06-19 HIGH 8.1 CVE-2017-18884 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth appli… Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,9502020-06-19