Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2025-54458 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscrip… Confluence 1.5.0+ Fix from $1,6002025-08-11 HIGH 7.5 CVE-2025-52931 Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to up… Confluence 1.5.0+ Fix from $1,9502025-08-11 HIGH 7.2 CVE-2025-44004 Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create … Confluence 1.5.0+ Fix from $1,9502025-08-11 MEDIUM 6.4 CVE-2025-48731 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscripti… Confluence 1.5.0+ Fix from $1,6002025-08-11 MEDIUM 6.5 CVE-2025-6226 Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts… Mattermost Server 9.11.17 / 10.5.7+ Fix from $1,6002025-07-18 MEDIUM 5.4 CVE-2025-46702 Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member… Mattermost Server 9.11.16 / 10.5.6+ Fix from $1,6002025-06-30 MEDIUM 5.4 CVE-2025-47871 Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membe… Mattermost Server 9.11.16 / 10.5.6+ Fix from $1,6002025-06-30 CRITICAL 9.9 CVE-2025-4981 Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archi… Mattermost Server 9.11.16 / 10.5.6+ Fix from $2,3002025-06-20 MEDIUM 5.4 CVE-2025-3230 Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon … Mattermost Server 9.11.13 / 10.5.4+ Fix from $1,6002025-05-30 MEDIUM 5.3 CVE-2025-31947 Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failu… Mattermost Server 9.11.12 / 10.4.5+ Fix from $1,6002025-05-15 HIGH 7.5 CVE-2025-35965 Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the Upd… Mattermost Server 9.11.11 / 10.4.3+ Fix from $1,9502025-04-24 HIGH 7.5 CVE-2025-41395 Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom po… Mattermost Server 9.11.11 / 10.4.3+ Fix from $1,9502025-04-24 MEDIUM 6.5 CVE-2025-31363 Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allow… Mattermost Server 9.11.10 / 10.4.3+ Fix from $1,6002025-04-16 MEDIUM 5.9 CVE-2025-27936 Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant ti… Mattermost Server 2.1.0 / 10.5.2+ Fix from $1,6002025-04-16 MEDIUM 5.4 CVE-2025-2475 Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which… Mattermost Server 9.11.10 / 10.4.4+ Fix from $1,6002025-04-14 HIGH 7.5 CVE-2025-30516 Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauth… Mattermost Mobile 2.26.0+ Fix from $1,9502025-04-14 MEDIUM 6.5 CVE-2025-1558 Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android a… Mattermost Mobile 2.25.1+ Fix from $1,6002025-03-24 MEDIUM 6.5 CVE-2025-30179 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attac… Mattermost Server 9.11.9 / 10.3.4+ Fix from $1,6002025-03-21 HIGH 8.8 CVE-2025-25068 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows auth… Mattermost Server 9.11.9 / 10.3.4+ Fix from $1,9502025-03-21 HIGH 8.8 CVE-2025-25274 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authen… Mattermost Server 9.11.9 / 10.3.4+ Fix from $1,9502025-03-21 HIGH 7.5 CVE-2025-25279EPSS 24% Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boar… Mattermost Server 9.11.8 / 10.2.3+ Fix from $1,9502025-02-24 MEDIUM 6.5 CVE-2025-20051 Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicat… Mattermost Server 9.11.8 / 10.2.3+ Fix from $1,6002025-02-24 MEDIUM 6.5 CVE-2025-24490 Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards… Mattermost Server 9.11.8 / 10.2.3+ Fix from $1,6002025-02-24 HIGH 8.8 CVE-2025-1412 Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the conver… Mattermost Server 9.11.7 / 10.4.2+ Fix from $1,9502025-02-24 MEDIUM 5.3 CVE-2025-0503 Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other m… Mattermost Server 9.11.7+ Fix from $1,6002025-02-14 HIGH 7.5 CVE-2025-20630 Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an… Mattermost Mobile 2.23.0+ Fix from $1,9502025-01-16 HIGH 7.5 CVE-2025-20621 Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing … Mattermost Server 9.11.6 / 10.0.4+ Fix from $1,9502025-01-16 HIGH 7.5 CVE-2025-20072 Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allo… Mattermost Mobile 2.23.0+ Fix from $1,9502025-01-16 MEDIUM 6.5 CVE-2025-20086 Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malici… Mattermost Server 9.11.6 / 10.0.4+ Fix from $1,6002025-01-15 MEDIUM 6.5 CVE-2025-20088 Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malici… Mattermost Server 9.11.6 / 10.0.4+ Fix from $1,6002025-01-15