Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2022-0708
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members…
Mattermost
after 6.3.0
HIGH 7.5
CVE-2021-37866
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attac…
Mattermost Boards
after 0.10.0
MEDIUM 6.5
CVE-2021-37864
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view conte…
Mattermost
after 6.1
MEDIUM 5.7
CVE-2021-37865
Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows auth…
Mattermost
after 6.2.0
MEDIUM 5.7
CVE-2021-37863
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-sid…
Mattermost Server
after 6.0
MEDIUM 5.4
CVE-2021-37862
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing u…
Mattermost Server
after 6.0
HIGH 7.5
CVE-2021-37861
Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.
Mattermost
after 6.0.2
MEDIUM 6.1
CVE-2021-37860
Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script i…
Mattermost
after 5.38
MEDIUM 6.1
CVE-2021-37859
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
Mattermost
5.34.5 / 5.35.4+
HIGH 7.5
CVE-2020-13891
An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, a…
Mattermost
1.31.2+
CRITICAL 9.8
CVE-2017-18908
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-ma…
Mattermost Server
3.9.2 / 3.10.2+
CRITICAL 9.8
CVE-2017-18915
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoin…
Mattermost Server
3.6.7 / 3.7.5+
CRITICAL 9.8
CVE-2017-18920
An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.
Mattermost Server
3.6.2+
HIGH 8.1
CVE-2017-18906
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody el…
Mattermost Server
3.9.2 / 3.10.2+
HIGH 7.5
CVE-2017-18917
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verifica…
Mattermost Server
3.6.7 / 3.7.5+
MEDIUM 6.1
CVE-2016-11084
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
Mattermost Server
2.1.0+
MEDIUM 6.1
CVE-2017-18907
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
Mattermost Server
3.9.2 / 3.10.2+
MEDIUM 6.1
CVE-2017-18913
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.
Mattermost Server
3.6.7 / 3.7.5+
MEDIUM 6.1
CVE-2017-18921
An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.
Mattermost Server
3.5.2+
MEDIUM 5.3
CVE-2017-18905
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mi…
Mattermost Server
3.9.2 / 3.10.2+
MEDIUM 5.3
CVE-2017-18914
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allo…
Mattermost Server
3.6.7 / 3.7.5+
MEDIUM 5.3
CVE-2017-18916
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission res…
Mattermost Server
3.6.7 / 3.7.5+
MEDIUM 5.3
CVE-2017-18919
An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.
Mattermost Server
3.6.3+
CRITICAL 9.8
CVE-2016-11074
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
Mattermost Server
3.0.0+
HIGH 7.5
CVE-2016-11069
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
Mattermost Server
3.2.0+
MEDIUM 6.5
CVE-2016-11072
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
Mattermost Server
3.0.2+
MEDIUM 6.5
CVE-2016-11078
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within …
Mattermost Server
3.0.0+
MEDIUM 6.1
CVE-2016-11071
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
Mattermost Server
3.1.0+
MEDIUM 6.1
CVE-2016-11073
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
Mattermost Server
3.0.0+
MEDIUM 6.1
CVE-2016-11079
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
Mattermost Server
3.0.0+