Filtered by vendor Mattermost
Subscriptions
Total
417 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-2475 | 1 Mattermost | 1 Mattermost | 2025-04-15 | 5.4 Medium |
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials. | ||||
CVE-2025-2424 | 1 Mattermost | 1 Mattermost | 2025-04-15 | 3.1 Low |
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation. | ||||
CVE-2025-24866 | 1 Mattermost | 1 Mattermost | 2025-04-11 | 2.7 Low |
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs. | ||||
CVE-2025-1398 | 1 Mattermost | 2 Mattermost, Mattermost Desktop | 2025-03-31 | 3.3 Low |
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection. | ||||
CVE-2025-25274 | 1 Mattermost | 1 Mattermost Server | 2025-03-27 | 4.3 Medium |
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels. | ||||
CVE-2025-27715 | 1 Mattermost | 1 Mattermost Server | 2025-03-27 | 3.3 Low |
Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them. | ||||
CVE-2025-27933 | 1 Mattermost | 1 Mattermost Server | 2025-03-27 | 5.4 Medium |
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public | ||||
CVE-2025-30179 | 1 Mattermost | 1 Mattermost Server | 2025-03-27 | 4.3 Medium |
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries. | ||||
CVE-2025-24920 | 1 Mattermost | 1 Mattermost Server | 2025-03-27 | 4.3 Medium |
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels | ||||
CVE-2025-25068 | 1 Mattermost | 1 Mattermost Server | 2025-03-27 | 7.5 High |
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes. | ||||
CVE-2025-1472 | 1 Mattermost | 1 Mattermost | 2025-03-19 | 4.3 Medium |
Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics. | ||||
CVE-2023-5920 | 2 Apple, Mattermost | 2 Macos, Mattermost Desktop | 2025-02-27 | 2.9 Low |
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input. | ||||
CVE-2024-21848 | 1 Mattermost | 1 Mattermost Server | 2025-02-27 | 3.1 Low |
Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel | ||||
CVE-2025-20086 | 1 Mattermost | 1 Mattermost | 2025-02-12 | 6.5 Medium |
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post. | ||||
CVE-2025-20088 | 1 Mattermost | 1 Mattermost | 2025-02-12 | 6.5 Medium |
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post. | ||||
CVE-2024-24975 | 1 Mattermost | 1 Mattermost Mobile | 2025-01-21 | 3.5 Low |
Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app. | ||||
CVE-2024-3872 | 1 Mattermost | 1 Mattermost Mobile | 2025-01-21 | 3.1 Low |
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link. | ||||
CVE-2025-20621 | 1 Mattermost | 1 Mattermost | 2025-01-16 | 6.5 Medium |
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel. | ||||
CVE-2025-20072 | 1 Mattermost | 2 Mattermost, Mattermost Mobile | 2025-01-16 | 6.5 Medium |
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input. | ||||
CVE-2025-21088 | 1 Mattermost | 1 Mattermost | 2025-01-15 | 6.5 Medium |
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input. |