Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2024-39807
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook …
Mattermost
9.5.6 / 9.8.1+
MEDIUM 5.4
CVE-2024-39361
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which a…
Mattermost
9.5.6 / 9.6.3+
MEDIUM 5.3
CVE-2024-36257
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server…
Mattermost
9.5.6+
MEDIUM 6.1
CVE-2024-37182
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a …
Mattermost Desktop
after 5.7.0
MEDIUM 5.7
CVE-2024-36255
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attack…
Mattermost Server
8.1.13 / 9.5.4+
MEDIUM 5.9
CVE-2024-32045
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linki…
Mattermost Server
8.1.13 / 9.5.4+
MEDIUM 6.3
CVE-2024-31859
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a pl…
Mattermost Server
8.1.13 / 9.5.4+
MEDIUM 6.5
CVE-2024-4183
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, whic…
Mattermost Server
8.1.12 / 9.4.5+
MEDIUM 6.5
CVE-2024-22091
Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user i…
Mattermost Server
8.1.12 / 9.5.3+
MEDIUM 6.5
CVE-2024-3872
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an una…
Mattermost Mobile
after 2.13.0
MEDIUM 6.5
CVE-2024-28949
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences…
Mattermost Server
8.1.11 / 9.3.3+
MEDIUM 6.5
CVE-2024-2447
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain ty…
Mattermost Server
8.1.11 / 9.3.3+
HIGH 8.8
CVE-2024-2450
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership wh…
Mattermost Server
8.1.10 / 9.2.6+
MEDIUM 6.1
CVE-2024-2445
Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 …
Mattermost Server
8.1.10 / 9.2.6+
MEDIUM 6.5
CVE-2024-28053
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an …
Mattermost Server
8.1.10+
MEDIUM 6.5
CVE-2024-24975
Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the…
Mattermost Mobile
2.13.0+
MEDIUM 6.5
CVE-2024-23493
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a …
Mattermost Server
8.1.9 / 9.2.5+
MEDIUM 6.5
CVE-2024-24988
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very lon…
Mattermost Server
8.1.8 / 9.1.5+
HIGH 8.8
CVE-2023-7114
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
Mattermost
2.10.1+
MEDIUM 6.1
CVE-2023-7113
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
Mattermost Server
8.1.7+
MEDIUM 6.5
CVE-2023-49809
Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoi…
Mattermost Server
after 9.1.0
MEDIUM 5.4
CVE-2023-6547
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permiss…
Mattermost Server
after 9.2.1
HIGH 7.5
CVE-2023-49607
Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playbook Plugin when updating the st…
Mattermost Server
after 9.2.1
MEDIUM 5.3
CVE-2023-46701
Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allow…
Mattermost Server
after 9.2.1
HIGH 8.8
CVE-2023-45316
Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing a…
Mattermost Server
after 9.2.1
HIGH 7.5
CVE-2023-45847
Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to send a specially crafted requ…
Mattermost Server
after 9.2.1
MEDIUM 5.3
CVE-2023-6459
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics …
Mattermost Server
7.8.14 / 8.1.5+
CRITICAL 9.8
CVE-2023-6458
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traver…
Mattermost Server
7.8.14 / 8.1.5+
HIGH 7.5
CVE-2023-48268
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to cons…
Mattermost
after 9.0.1
MEDIUM 6.1
CVE-2023-47168
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" aft…
Mattermost
after 9.0.1