Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2025-21083
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a mali…
Mattermost Mobile
2.23.0+
MEDIUM 6.5
CVE-2025-20036
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a mali…
Mattermost Mobile
2.23.0+
MEDIUM 6.5
CVE-2025-21088
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to a…
Mattermost Server
9.11.6 / 10.0.4+
MEDIUM 6.5
CVE-2025-20033
Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny…
Mattermost Server
9.11.6 / 10.0.4+
MEDIUM 5.3
CVE-2025-22445
Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive …
Mattermost Server
10.3.0+
MEDIUM 5.5
CVE-2024-11358
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files…
Mattermost Mobile
2.22.2+
MEDIUM 6.5
CVE-2024-54083
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allow…
Mattermost Server
9.5.13 / 9.11.5+
MEDIUM 5.3
CVE-2024-11599
Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an u…
Mattermost Server
9.5.12 / 9.11.4+
HIGH 7.5
CVE-2024-47401
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks w…
Mattermost Server
9.5.10 / 9.10.3+
MEDIUM 6.5
CVE-2024-47003
Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker…
Mattermost Server
9.5.9+
MEDIUM 5.4
CVE-2024-45843
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker …
Mattermost Server
9.5.9+
MEDIUM 5.4
CVE-2024-42406
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived c…
Mattermost Server
9.5.9 / 9.9.3+
MEDIUM 6.5
CVE-2024-45835
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse ot…
Mattermost Desktop
5.9.0+
MEDIUM 5.3
CVE-2024-39772
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality scre…
Mattermost Desktop
5.9.0+
MEDIUM 6.5
CVE-2024-45833
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which …
Mattermost Mobile
2.19.0+
HIGH 7.8
CVE-2024-39613
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able …
Mattermost Desktop
5.9.0+
HIGH 8.8
CVE-2024-40886
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for r…
Mattermost
9.5.8 / 9.8.3+
HIGH 7.2
CVE-2024-8071
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system adm…
Mattermost
9.5.8 / 9.8.3+
MEDIUM 5.3
CVE-2024-42411
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a …
Mattermost
9.5.8 / 9.8.3+
MEDIUM 6.5
CVE-2024-39836
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create ses…
Mattermost
9.5.8 / 9.8.3+
HIGH 7.1
CVE-2024-41144
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are e…
Mattermost Server
9.5.7 / 9.7.6+
CRITICAL 9.6
CVE-2024-39777
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local …
Mattermost
9.5.7 / 9.7.6+
HIGH 8.7
CVE-2024-39832
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malici…
Mattermost
9.5.7 / 9.7.6+
MEDIUM 6.5
CVE-2024-39274
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the …
Mattermost
9.5.7 / 9.7.6+
MEDIUM 5.4
CVE-2024-39837
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary cha…
Mattermost Server
9.5.7+
MEDIUM 6.4
CVE-2024-36492
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing user…
Mattermost
9.5.7 / 9.7.6+
MEDIUM 6.5
CVE-2024-39767
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which …
Mattermost Mobile
2.17.0+
MEDIUM 5.3
CVE-2024-32945
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the cont…
Mattermost Mobile
2.17.0+
MEDIUM 6.5
CVE-2024-6428
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows…
Mattermost
9.5.6 / 9.6.3+
MEDIUM 5.9
CVE-2024-39830
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time co…
Mattermost
9.5.6 / 9.6.3+