VYPR

Mattermost

by Mattermost

Source repositories

CVEs (594)

  • CVE-2024-50052MedOct 29, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.

  • CVE-2024-10241MedOct 29, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.

  • CVE-2024-43105MedAug 23, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.

  • CVE-2024-39839MedAug 1, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would…

  • CVE-2024-4183MedApr 26, 2024
    risk 0.21cvss 4.3epss 0.01

    Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions…

  • CVE-2024-4182MedApr 26, 2024
    risk 0.21cvss 4.3epss 0.01

    Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.

  • CVE-2024-32046MedApr 26, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are…

  • CVE-2024-28949MedApr 5, 2024
    risk 0.21cvss 4.3epss 0.01

    Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.

  • CVE-2024-1402MedFeb 9, 2024
    risk 0.21cvss 4.3epss 0.01

    Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user…

  • CVE-2023-48732MedJan 2, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.

  • CVE-2022-1003LowMar 18, 2022
    risk 0.21cvss 3.3epss 0.01

    One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.

  • CVE-2016-11081MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser.

  • CVE-2016-11080MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details.

  • CVE-2016-11065MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.

  • CVE-2017-18878MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.

  • CVE-2017-18872MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.

  • CVE-2019-20890MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.

  • CVE-2019-20887MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.

  • CVE-2026-15754MedAug 17, 2026
    risk 0.20cvss 4.2epss 0.00

    Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ABAC (attribute-based access…

  • CVE-2026-20796LowFeb 13, 2026
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID:…

Page 24 of 30