Vendor CVEs
Mattermost
All CVEs
649 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55070 | Med | 0.35 | 6.5 | 0.00 | Nov 14, 2025 | Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events | ||
| CVE-2025-9076 | Med | 0.35 | 6.5 | 0.00 | Sep 15, 2025 | Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects… | ||
| CVE-2025-6226 | Med | 0.35 | 6.5 | 0.00 | Jul 18, 2025 | Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the… | ||
| CVE-2025-41395 | Med | 0.35 | 6.5 | 0.00 | Apr 24, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and… | ||
| CVE-2025-35965 | Med | 0.35 | 6.5 | 0.00 | Apr 24, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions… | ||
| CVE-2025-27933 | Med | 0.35 | 5.4 | 0.00 | Mar 21, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public | ||
| CVE-2024-54682 | Med | 0.35 | 6.5 | 0.00 | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin. | ||
| CVE-2024-54083 | Med | 0.35 | 6.5 | 0.01 | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post. | ||
| CVE-2024-42406 | Med | 0.35 | 5.4 | 0.00 | Sep 26, 2024 | Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged… | ||
| CVE-2023-2000 | Med | 0.35 | 5.4 | 0.00 | May 2, 2023 | Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website | ||
| CVE-2022-0903 | Med | 0.35 | 5.3 | 0.01 | Mar 10, 2022 | A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body. | ||
| CVE-2017-18919 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation. | ||
| CVE-2017-18914 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist. | ||
| CVE-2016-11078 | Med | 0.35 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI. | ||
| CVE-2016-11072 | Med | 0.35 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled. | ||
| CVE-2017-18902 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints. | ||
| CVE-2017-18899 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting. | ||
| CVE-2017-18887 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members. | ||
| CVE-2017-18874 | Med | 0.35 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal. | ||
| CVE-2019-20884 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post. | ||
| CVE-2019-20882 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team. | ||
| CVE-2019-20877 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled. | ||
| CVE-2019-20876 | Med | 0.35 | 5.4 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy. | ||
| CVE-2019-20875 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed. | ||
| CVE-2018-21265 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications). | ||
| CVE-2018-21259 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel. | ||
| CVE-2018-21257 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API. | ||
| CVE-2020-14452 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014. | ||
| CVE-2019-20850 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout. | ||
| CVE-2019-20849 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout. | ||
| CVE-2019-20847 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any channel. | ||
| CVE-2026-16048 | Med | 0.34 | 6.3 | 0.00 | Aug 17, 2026 | Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory… | ||
| CVE-2026-10527 | Med | 0.34 | 6.3 | 0.00 | Aug 17, 2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges and perform admin-only operations via the Boards REST API or… | ||
| CVE-2025-27936 | Med | 0.34 | 5.3 | 0.00 | Apr 16, 2025 | Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin… | ||
| CVE-2024-42411 | Med | 0.34 | 5.3 | 0.00 | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older. | ||
| CVE-2024-6428 | Med | 0.34 | 5.3 | 0.00 | Jul 3, 2024 | Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause… | ||
| CVE-2023-6459 | Med | 0.34 | 5.3 | 0.01 | Dec 6, 2023 | Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs. | ||
| CVE-2025-54458 | Med | 0.33 | 5.0 | 0.00 | Aug 11, 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint. | ||
| CVE-2017-18907 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header. | ||
| CVE-2016-11084 | Med | 0.33 | 6.1 | 0.00 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF. | ||
| CVE-2016-11083 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window. | ||
| CVE-2016-11082 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link. | ||
| CVE-2016-11079 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL. | ||
| CVE-2016-11073 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting. | ||
| CVE-2016-11071 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place. | ||
| CVE-2016-11063 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview. | ||
| CVE-2017-18904 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file. | ||
| CVE-2017-18897 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection. | ||
| CVE-2017-18893 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS. | ||
| CVE-2017-18892 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized. |
- risk 0.35cvss 6.5epss 0.00
Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events
- risk 0.35cvss 6.5epss 0.00
Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects…
- risk 0.35cvss 6.5epss 0.00
Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the…
- risk 0.35cvss 6.5epss 0.00
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and…
- risk 0.35cvss 6.5epss 0.00
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions…
- risk 0.35cvss 5.4epss 0.00
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public
- risk 0.35cvss 6.5epss 0.00
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.
- risk 0.35cvss 6.5epss 0.01
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.
- risk 0.35cvss 5.4epss 0.00
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged…
- risk 0.35cvss 5.4epss 0.00
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
- risk 0.35cvss 5.3epss 0.01
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any channel.
- risk 0.34cvss 6.3epss 0.00
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory…
- risk 0.34cvss 6.3epss 0.00
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges and perform admin-only operations via the Boards REST API or…
- risk 0.34cvss 5.3epss 0.00
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin…
- risk 0.34cvss 5.3epss 0.00
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.
- risk 0.34cvss 5.3epss 0.00
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause…
- risk 0.34cvss 5.3epss 0.01
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.
- risk 0.33cvss 5.0epss 0.00
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
- risk 0.33cvss 6.1epss 0.00
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.
Page 5 of 13