Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-21083 Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a mali… Mattermost Mobile 2.23.0+ Fix from $1,6002025-01-15 MEDIUM 6.5 CVE-2025-20036 Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a mali… Mattermost Mobile 2.23.0+ Fix from $1,6002025-01-15 MEDIUM 6.5 CVE-2025-21088 Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to a… Mattermost Server 9.11.6 / 10.0.4+ Fix from $1,6002025-01-15 MEDIUM 6.5 CVE-2025-20033 Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny… Mattermost Server 9.11.6 / 10.0.4+ Fix from $1,6002025-01-09 MEDIUM 5.3 CVE-2025-22445 Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive … Mattermost Server 10.3.0+ Fix from $1,6002025-01-09 MEDIUM 5.5 CVE-2024-11358 Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files… Mattermost Mobile 2.22.2+ Fix from $1,6002024-12-16 MEDIUM 6.5 CVE-2024-54083 Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allow… Mattermost Server 9.5.13 / 9.11.5+ Fix from $1,6002024-12-16 MEDIUM 5.3 CVE-2024-11599 Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an u… Mattermost Server 9.5.12 / 9.11.4+ Fix from $1,6002024-11-28 HIGH 7.5 CVE-2024-47401 Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks w… Mattermost Server 9.5.10 / 9.10.3+ Fix from $1,9502024-10-29 MEDIUM 6.5 CVE-2024-47003 Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker… Mattermost Server 9.5.9+ Fix from $1,6002024-09-26 MEDIUM 5.4 CVE-2024-45843 Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker … Mattermost Server 9.5.9+ Fix from $1,6002024-09-26 MEDIUM 5.4 CVE-2024-42406 Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived c… Mattermost Server 9.5.9 / 9.9.3+ Fix from $1,6002024-09-26 MEDIUM 6.5 CVE-2024-45835 Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse ot… Mattermost Desktop 5.9.0+ Fix from $1,6002024-09-16 MEDIUM 5.3 CVE-2024-39772 Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality scre… Mattermost Desktop 5.9.0+ Fix from $1,6002024-09-16 MEDIUM 6.5 CVE-2024-45833 Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which … Mattermost Mobile 2.19.0+ Fix from $1,6002024-09-16 HIGH 7.8 CVE-2024-39613 Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able … Mattermost Desktop 5.9.0+ Fix from $1,9502024-09-16 HIGH 8.8 CVE-2024-40886 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for r… Mattermost 9.5.8 / 9.8.3+ Fix from $1,9502024-08-22 HIGH 7.2 CVE-2024-8071 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system adm… Mattermost 9.5.8 / 9.8.3+ Fix from $1,9502024-08-22 MEDIUM 5.3 CVE-2024-42411 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a … Mattermost 9.5.8 / 9.8.3+ Fix from $1,6002024-08-22 MEDIUM 6.5 CVE-2024-39836 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create ses… Mattermost 9.5.8 / 9.8.3+ Fix from $1,6002024-08-22 HIGH 7.1 CVE-2024-41144 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are e… Mattermost Server 9.5.7 / 9.7.6+ Fix from $1,9502024-08-01 CRITICAL 9.6 CVE-2024-39777 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local … Mattermost 9.5.7 / 9.7.6+ Fix from $2,3002024-08-01 HIGH 8.7 CVE-2024-39832 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malici… Mattermost 9.5.7 / 9.7.6+ Fix from $1,9502024-08-01 MEDIUM 6.5 CVE-2024-39274 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the … Mattermost 9.5.7 / 9.7.6+ Fix from $1,6002024-08-01 MEDIUM 5.4 CVE-2024-39837 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary cha… Mattermost Server 9.5.7+ Fix from $1,6002024-08-01 MEDIUM 6.4 CVE-2024-36492 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing user… Mattermost 9.5.7 / 9.7.6+ Fix from $1,6002024-08-01 MEDIUM 6.5 CVE-2024-39767 Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which … Mattermost Mobile 2.17.0+ Fix from $1,6002024-07-15 MEDIUM 5.3 CVE-2024-32945 Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the cont… Mattermost Mobile 2.17.0+ Fix from $1,6002024-07-15 MEDIUM 6.5 CVE-2024-6428 Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows… Mattermost 9.5.6 / 9.6.3+ Fix from $1,6002024-07-03 MEDIUM 5.9 CVE-2024-39830 Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time co… Mattermost 9.5.6 / 9.6.3+ Fix from $1,6002024-07-03