Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2023-2788
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persi…
Mattermost
after 7.9.3
MEDIUM 5.3
CVE-2023-2808
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to tr…
Mattermost
7.1.9 / 7.8.4+
HIGH 8.8
CVE-2023-2515
Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to syst…
Mattermost Server
7.1.8 / 7.7.4+
HIGH 7.5
CVE-2023-2514
Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization.
Mattermost
after 7.9.1
MEDIUM 5.4
CVE-2023-2000
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
Mattermost Desktop
after 5.2.2
CRITICAL 9.1
CVE-2023-2193
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code t…
Mattermost
Mitigation only
HIGH 7.5
CVE-2023-1831
Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental …
Mattermost Server
7.7.3 / 7.8.2+
MEDIUM 6.5
CVE-2023-1775
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all use…
Mattermost Server
7.1.6+
MEDIUM 5.4
CVE-2023-1774
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an at…
Mattermost Server
7.1.6+
MEDIUM 5.4
CVE-2023-1776
Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
Mattermost Server
7.1.6+
MEDIUM 5.3
CVE-2023-1777
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the con…
Mattermost Server
7.1.6+
MEDIUM 6.1
CVE-2023-1421
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behal…
Mattermost Server
7.7.0+
MEDIUM 6.5
CVE-2023-27263
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team…
Mattermost
after 7.1.4
MEDIUM 6.5
CVE-2023-27264
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks…
Mattermost
after 7.1.4
MEDIUM 6.5
CVE-2022-4045
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoint…
Mattermost
Mitigation only
MEDIUM 6.5
CVE-2022-4019
A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to …
Mattermost
Mitigation only
MEDIUM 6.5
CVE-2022-4044
A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.
Mattermost
7.4+
MEDIUM 6.5
CVE-2022-3257
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which a…
Mattermost Server
7.2.0+
MEDIUM 6.5
CVE-2022-3147
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated…
Mattermost Server
7.1.0+
MEDIUM 6.5
CVE-2022-2401
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by …
Mattermost Server
6.3.9 / 6.5.2+
MEDIUM 6.5
CVE-2022-2406
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenti…
Mattermost
after 6.5.1
MEDIUM 5.3
CVE-2022-2366
Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations …
Mattermost Server
6.3.9 / 6.5.2+
MEDIUM 6.5
CVE-2022-1982
Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG atta…
Mattermost Server
6.3.8 / 6.4.3+
HIGH 8.8
CVE-2022-1548
Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membe…
Playbooks
after 1.25.0
HIGH 8.8
CVE-2022-1384
Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an auth…
Mattermost Server
6.5.0+
MEDIUM 6.5
CVE-2022-1333
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorize…
Playbooks
after 1.24.0
MEDIUM 6.5
CVE-2022-1337
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authentica…
Mattermost Server
5.37.9 / 6.2.5+
MEDIUM 5.4
CVE-2022-1002
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users w…
Mattermost
6.4.0+
HIGH 7.5
CVE-2022-0903
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server…
Mattermost Server
5.37.8 / 6.1.3+
MEDIUM 6.5
CVE-2022-0904
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via …
Mattermost Server
5.37.8 / 6.1.3+