VYPR

Mattermost

by Mattermost

Source repositories

CVEs (594)

  • CVE-2019-20889MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.

  • CVE-2019-20883MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post.

  • CVE-2019-20879MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.

  • CVE-2019-20878MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.

  • CVE-2018-21261MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.

  • CVE-2018-21255MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel.

  • CVE-2018-21254MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.

  • CVE-2018-21253MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.

  • CVE-2017-18870MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.

  • CVE-2019-20870MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited flag after changing a post's file ID.

  • CVE-2019-20869MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel.

  • CVE-2019-20867MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post.

  • CVE-2019-20866MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address in an IP packet header, for obtaining IP address information was mishandled.

  • CVE-2026-10556MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar…

  • CVE-2026-6046MedJun 12, 2026
    risk 0.27cvss 5.3epss 0.00

    Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged attacker to intercept private messages sent by plugins via…

  • CVE-2026-2456MedMar 16, 2026
    risk 0.27cvss 5.3epss 0.00

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker to cause server memory exhaustion and denial of service via a malicious…

  • CVE-2025-3913MedMay 29, 2025
    risk 0.27cvss 5.3epss 0.00

    Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate permissions when changing team privacy settings, allowing team administrators without the 'invite user' permission to access and modify team invite IDs via the…

  • CVE-2024-39613MedSep 16, 2024
    risk 0.27cvss 5.3epss 0.00

    Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.

  • CVE-2023-5969MedNov 6, 2023
    risk 0.27cvss 5.3epss 0.01

    Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.

  • CVE-2023-3586MedJul 17, 2023
    risk 0.27cvss 4.2epss 0.00

    Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared public Boards to remain accessible.

Page 18 of 30