Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-48268
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to cons…
Mattermost
after 9.0.1
MEDIUM 6.1
CVE-2023-47168
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" aft…
Mattermost
after 9.0.1
MEDIUM 5.3
CVE-2023-48369
Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially o…
Mattermost
after 9.0.1
HIGH 7.5
CVE-2023-40703
Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessiv…
Mattermost
after 9.0.1
MEDIUM 5.4
CVE-2023-35075
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML…
Mattermost
after 8.1.3
MEDIUM 5.3
CVE-2023-5969
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/r…
Mattermost
after 8.1.2
MEDIUM 5.3
CVE-2023-5875
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a …
Mattermost Desktop
5.5.1+
MEDIUM 5.3
CVE-2023-5876
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial…
Mattermost Desktop
5.5.1+
MEDIUM 5.5
CVE-2023-5339
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including pa…
Mattermost Desktop
after 5.4.0
HIGH 7.5
CVE-2023-5330
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to t…
Mattermost Server
7.8.11 / 8.0.3+
MEDIUM 6.5
CVE-2023-5333
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sendin…
Mattermost Server
7.8.11 / 8.0.3+
MEDIUM 5.3
CVE-2023-5331
Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file infor…
Mattermost Server
7.8.11 / 8.0.3+
MEDIUM 6.5
CVE-2023-5196
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_p…
Mattermost
7.8.10 / 8.0.2+
MEDIUM 5.4
CVE-2023-5195
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not p…
Mattermost
7.8.10 / 8.0.2+
HIGH 8.2
CVE-2023-4478
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thu…
Mattermost Server
7.8.9 / 7.10.5+
HIGH 7.5
CVE-2023-4108
Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged
Mattermost
7.8.8 / 7.9.6+
MEDIUM 6.5
CVE-2023-4106
Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to …
Mattermost
7.8.8 / 7.9.6+
MEDIUM 6.5
CVE-2023-4107
Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin'…
Mattermost
7.8.8 / 7.9.6+
HIGH 8.1
CVE-2023-3615
Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept t…
Mattermost
2.5.1+
MEDIUM 6.5
CVE-2023-3593
Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.
Mattermost Server
7.8.7 / 7.9.5+
HIGH 8.2
CVE-2023-3591
Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
Mattermost Server
7.8.7 / 7.9.5+
HIGH 8.1
CVE-2023-3581
Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.
Mattermost Server
7.8.7 / 7.9.5+
HIGH 7.5
CVE-2023-3590
Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.
Mattermost Server
7.10.3+
MEDIUM 5.4
CVE-2023-3586
Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared …
Mattermost Server
7.8.7 / 7.9.5+
MEDIUM 6.5
CVE-2023-2792
Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg com…
Mattermost
after 7.9.3
MEDIUM 6.5
CVE-2023-2793
Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-s…
Mattermost
after 7.9.2
MEDIUM 6.5
CVE-2023-2797
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink…
Mattermost
after 7.8.4
MEDIUM 6.5
CVE-2023-2831
Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message conta…
Mattermost
after 7.9.3
MEDIUM 6.5
CVE-2023-2784
Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install…
Mattermost
after 7.9.3
MEDIUM 6.5
CVE-2023-2787
Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message thre…
Mattermost
after 7.9.3