Vulnerability index

Browse CVEs

381 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-0708 Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members… Mattermost after 6.3.0 Fix from $1,6002022-02-21 HIGH 7.5 CVE-2021-37866 Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attac… Mattermost Boards after 0.10.0 Fix from $1,9502022-01-18 MEDIUM 6.5 CVE-2021-37864 Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view conte… Mattermost after 6.1 Fix from $1,6002022-01-18 MEDIUM 5.7 CVE-2021-37865 Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows auth… Mattermost after 6.2.0 Fix from $1,6002022-01-18 MEDIUM 5.7 CVE-2021-37863 Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-sid… Mattermost Server after 6.0 Fix from $1,6002021-12-17 MEDIUM 5.4 CVE-2021-37862 Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing u… Mattermost Server after 6.0 Fix from $1,6002021-12-17 HIGH 7.5 CVE-2021-37861 Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails. Mattermost after 6.0.2 Fix from $1,9502021-12-09 MEDIUM 6.1 CVE-2021-37860 Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script i… Mattermost after 5.38 Fix from $1,6002021-09-22 MEDIUM 6.1 CVE-2021-37859 Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost. Mattermost 5.34.5 / 5.35.4+ Fix from $1,6002021-08-05 HIGH 7.5 CVE-2020-13891 An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, a… Mattermost 1.31.2+ Fix from $1,9502020-06-26 CRITICAL 9.8 CVE-2017-18908 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-ma… Mattermost Server 3.9.2 / 3.10.2+ Fix from $2,3002020-06-19 CRITICAL 9.8 CVE-2017-18915 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoin… Mattermost Server 3.6.7 / 3.7.5+ Fix from $2,3002020-06-19 CRITICAL 9.8 CVE-2017-18920 An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy. Mattermost Server 3.6.2+ Fix from $2,3002020-06-19 HIGH 8.1 CVE-2017-18906 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody el… Mattermost Server 3.9.2 / 3.10.2+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2017-18917 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verifica… Mattermost Server 3.6.7 / 3.7.5+ Fix from $1,9502020-06-19 MEDIUM 6.1 CVE-2016-11084 An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF. Mattermost Server 2.1.0+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18907 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header. Mattermost Server 3.9.2 / 3.10.2+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18913 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page. Mattermost Server 3.6.7 / 3.7.5+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18921 An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page. Mattermost Server 3.5.2+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18905 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mi… Mattermost Server 3.9.2 / 3.10.2+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18914 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allo… Mattermost Server 3.6.7 / 3.7.5+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18916 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission res… Mattermost Server 3.6.7 / 3.7.5+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18919 An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation. Mattermost Server 3.6.3+ Fix from $1,6002020-06-19 CRITICAL 9.8 CVE-2016-11074 An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused. Mattermost Server 3.0.0+ Fix from $2,3002020-06-19 HIGH 7.5 CVE-2016-11069 An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change. Mattermost Server 3.2.0+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2016-11072 An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled. Mattermost Server 3.0.2+ Fix from $1,6002020-06-19 MEDIUM 6.5 CVE-2016-11078 An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within … Mattermost Server 3.0.0+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2016-11071 An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place. Mattermost Server 3.1.0+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2016-11073 An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting. Mattermost Server 3.0.0+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2016-11079 An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL. Mattermost Server 3.0.0+ Fix from $1,6002020-06-19