VYPR

Mattermost

by Mattermost

Source repositories

CVEs (566)

  • CVE-2026-3117MedMay 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab instance {option}}} or the {{/gitlab…

  • CVE-2026-2476HigMar 16, 2026
    risk 0.42cvss 7.6epss 0.00

    Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606

  • CVE-2026-24458HigMar 16, 2026
    risk 0.42cvss 7.5epss 0.00

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Mattermost Advisory ID:…

  • CVE-2025-9072HigSep 15, 2025
    risk 0.42cvss 7.6epss 0.00

    Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an…

  • CVE-2025-1558MedMar 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.

  • CVE-2025-20630MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.01

    Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.

  • CVE-2025-20621MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post…

  • CVE-2025-20072MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.01

    Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.

  • CVE-2025-21083MedJan 15, 2025
    risk 0.42cvss 6.5epss 0.01

    Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

  • CVE-2025-20088MedJan 15, 2025
    risk 0.42cvss 6.5epss 0.01

    Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

  • CVE-2025-20086MedJan 15, 2025
    risk 0.42cvss 6.5epss 0.00

    Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

  • CVE-2025-20036MedJan 15, 2025
    risk 0.42cvss 6.5epss 0.01

    Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

  • CVE-2025-21088MedJan 15, 2025
    risk 0.42cvss 6.5epss 0.01

    Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.

  • CVE-2024-2447MedApr 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.

  • CVE-2023-46701MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID

  • CVE-2023-5196MedSep 29, 2023
    risk 0.42cvss 6.5epss 0.01

    Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable…

  • CVE-2023-5195MedSep 29, 2023
    risk 0.42cvss 6.5epss 0.00

    Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

  • CVE-2023-2793MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message.

  • CVE-2023-2792MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command.

  • CVE-2023-2787MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.

Page 5 of 29