Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost Server MEDIUM 6.5
CVE-2026-10080

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authentic…

Fix unknown
Fix from $4,000 2026-08-17
Mattermost Server MEDIUM 6.3
CVE-2026-16048

Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles w…

Fix unknown
Fix from $4,000 2026-08-17
Mattermost Server MEDIUM 6.3
CVE-2026-10527

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which all…

Fix unknown
Fix from $4,000 2026-08-17
Mattermost Server MEDIUM 5.4
CVE-2026-16044

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive impo…

Fix unknown
Fix from $4,000 2026-08-17
Mattermost Server MEDIUM 6.5
CVE-2026-14298

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when proces…

No fix yet
Fix from $4,000 2026-08-13
Mattermost Server MEDIUM 5.5
CVE-2026-7521

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin…

Fix: 10.11.21 / 11.6.6+
Fix from $1,600 2026-07-28
Mattermost Server MEDIUM 6.5
CVE-2026-10819

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file…

Fix: 10.11.21 / 11.6.6+
Fix from $1,600 2026-07-27
Mattermost Desktop MEDIUM 6.5
CVE-2026-8075

Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows…

Fix: 5.13.6 / 6.2.1+
Fix from $1,600 2026-07-17
Mattermost Desktop MEDIUM 6.5
CVE-2026-9602

Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a mal…

Fix: 5.13.7 / 6.2.1+
Fix from $1,600 2026-07-17
Mattermost Server MEDIUM 6.5
CVE-2026-9571

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, w…

Fix: 10.11.20 / 11.6.5+
Fix from $1,600 2026-07-13
Mattermost Server MEDIUM 5.4
CVE-2026-9597

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-l…

Fix: 11.6.5 / 11.7.3+
Fix from $1,600 2026-07-13
Mattermost Server MEDIUM 6.5
CVE-2026-6850

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field value…

Fix: 10.11.20 / 11.6.5+
Fix from $1,600 2026-07-13
Mattermost Server MEDIUM 6.5
CVE-2026-10106

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches th…

Fix: 10.11.20 / 11.6.5+
Fix from $1,600 2026-07-13
Mattermost Server MEDIUM 5.4
CVE-2026-10085

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private…

Fix: 10.11.20 / 11.6.5+
Fix from $1,600 2026-07-13
Mattermost Server MEDIUM 6.5
CVE-2026-4339

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in…

Fix: 10.11.19 / 11.5.7+
Fix from $1,600 2026-06-26
Mattermost Server MEDIUM 6.4
CVE-2026-6062

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subsc…

Fix: 10.11.18 / 11.5.6+
Fix from $1,600 2026-06-22
Mattermost Server MEDIUM 6.4
CVE-2026-6673

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callba…

Fix: 10.11.18 / 11.5.6+
Fix from $1,600 2026-06-22
Mattermost Server MEDIUM 5.4
CVE-2026-5139

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{se…

Fix: 10.11.18 / 11.5.6+
Fix from $1,600 2026-06-22
Mattermost Desktop MEDIUM 6.5
CVE-2026-8683

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows …

Fix: after 6.1.5
Fix from $1,600 2026-06-15
Mattermost Desktop HIGH 7.7
CVE-2026-6517

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermo…

Fix: after 6.1.5
Fix from $1,950 2026-06-15
Mattermost Server HIGH 8.8
CVE-2026-7387

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authoriz…

Fix: 10.11.17 / 11.5.5+
Fix from $1,950 2026-06-12
Mattermost Server HIGH 7.6
CVE-2026-6961

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received …

Fix: 10.11.17 / 11.5.5+
Fix from $1,950 2026-06-12
Mattermost Server HIGH 7.2
CVE-2026-6739

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patchin…

Fix: 10.11.17 / 11.5.5+
Fix from $1,950 2026-06-12
Mattermost Server MEDIUM 6.5
CVE-2026-7184

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, whi…

Fix: 10.11.17 / 11.5.5+
Fix from $1,600 2026-06-12
Mattermost Server MEDIUM 5.3
CVE-2026-6046

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot…

Fix: 10.11.17 / 11.5.5+
Fix from $1,600 2026-06-12
Mattermost Server MEDIUM 6.5
CVE-2026-4915

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attac…

Fix: 10.11.15 / 11.4.5+
Fix from $1,600 2026-05-25
Mattermost Server MEDIUM 5.4
CVE-2026-28735

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback …

Fix: 10.11.15 / 11.4.5+
Fix from $1,600 2026-05-22
Mattermost Server HIGH 7.5
CVE-2026-5308

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP…

Fix: 10.11.15 / 11.4.5+
Fix from $1,950 2026-05-22
Mattermost Server HIGH 7.5
CVE-2026-5740

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket fra…

Fix: 10.11.15 / 11.4.5+
Fix from $1,950 2026-05-22
Mattermost Server MEDIUM 6.5
CVE-2026-5755

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset …

Fix: 10.11.15 / 11.4.5+
Fix from $1,600 2026-05-22