Mattermost
by Mattermost
Source repositories
CVEs (594)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-50052 | Med | 0.21 | 4.3 | 0.00 | Oct 29, 2024 | Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post. | ||
| CVE-2024-10241 | Med | 0.21 | 4.3 | 0.00 | Oct 29, 2024 | Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K. | ||
| CVE-2024-43105 | Med | 0.21 | 4.3 | 0.00 | Aug 23, 2024 | Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once. | ||
| CVE-2024-39839 | Med | 0.21 | 4.3 | 0.00 | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would… | ||
| CVE-2024-4183 | Med | 0.21 | 4.3 | 0.01 | Apr 26, 2024 | Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions… | ||
| CVE-2024-4182 | Med | 0.21 | 4.3 | 0.01 | Apr 26, 2024 | Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status. | ||
| CVE-2024-32046 | Med | 0.21 | 4.3 | 0.00 | Apr 26, 2024 | Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are… | ||
| CVE-2024-28949 | Med | 0.21 | 4.3 | 0.01 | Apr 5, 2024 | Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service. | ||
| CVE-2024-1402 | Med | 0.21 | 4.3 | 0.01 | Feb 9, 2024 | Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user… | ||
| CVE-2023-48732 | Med | 0.21 | 4.3 | 0.00 | Jan 2, 2024 | Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel. | ||
| CVE-2022-1003 | Low | 0.21 | 3.3 | 0.01 | Mar 18, 2022 | One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | ||
| CVE-2016-11081 | Med | 0.21 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser. | ||
| CVE-2016-11080 | Med | 0.21 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details. | ||
| CVE-2016-11065 | Med | 0.21 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance. | ||
| CVE-2017-18878 | Med | 0.21 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session. | ||
| CVE-2017-18872 | Med | 0.21 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider. | ||
| CVE-2019-20890 | Med | 0.21 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions. | ||
| CVE-2019-20887 | Med | 0.21 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts. | ||
| CVE-2026-15754 | Med | 0.20 | 4.2 | 0.00 | Aug 17, 2026 | Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ABAC (attribute-based access… | ||
| CVE-2026-20796 | Low | 0.20 | 3.1 | 0.00 | Feb 13, 2026 | Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID:… |
- risk 0.21cvss 4.3epss 0.00
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
- risk 0.21cvss 4.3epss 0.00
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
- risk 0.21cvss 4.3epss 0.00
Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.
- risk 0.21cvss 4.3epss 0.00
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would…
- risk 0.21cvss 4.3epss 0.01
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions…
- risk 0.21cvss 4.3epss 0.01
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
- risk 0.21cvss 4.3epss 0.00
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are…
- risk 0.21cvss 4.3epss 0.01
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
- risk 0.21cvss 4.3epss 0.01
Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user…
- risk 0.21cvss 4.3epss 0.00
Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.
- risk 0.21cvss 3.3epss 0.01
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
- risk 0.21cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser.
- risk 0.21cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details.
- risk 0.21cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.
- risk 0.21cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
- risk 0.21cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
- risk 0.21cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
- risk 0.21cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
- risk 0.20cvss 4.2epss 0.00
Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ABAC (attribute-based access…
- risk 0.20cvss 3.1epss 0.00
Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID:…
Page 24 of 30