mattermost

576 tracked vulnerabilities.

CVE-2022-1337 MEDIUM
Mattermost Server < 6.4.2 - Authenticated Denial of Service via Image Proxy Memory Allocation
Apr 13, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1333 LOW
Mattermost Playbooks < 1.24.0 - Authenticated Denial of Service via Webhook Limit Bypass
Apr 13, 2022
CVSS 3.5
EPSS 0.00
CVE-2022-1332 MEDIUM
Mattermost Server 5.37.0-5.37.8 and 6.4.0-6.4.1 - Authenticated Privilege Escalation via API
Apr 13, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-1003 LOW
Mattermost <6.3.0 - Privilege Escalation
Mar 18, 2022
CVSS 3.3
EPSS 0.00
CVE-2022-1002 LOW
Mattermost < 6.4.0 - Cross-Site Scripting via Guest User Email Invitation
Mar 18, 2022
CVSS 2.0
EPSS 0.00
CVE-2022-0904 MEDIUM
Mattermost Server <= 6.3.2 - Denial of Service via Malicious Apple Pages Document
Mar 10, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-0903 MEDIUM
Mattermost Server <= 6.3.2 - Denial of Service via SAML Login POST Body
Mar 10, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-0708 MEDIUM
Mattermost <6.3.0 - Info Disclosure
Feb 21, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-37867 MEDIUM
Mattermost Boards < 0.10.0 - Authenticated Sensitive Information Exposure via API
Jan 18, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-37866 MEDIUM
Mattermost Boards < 0.10.0 - Insufficient Session Expiration
Jan 18, 2022
CVSS 4.7
EPSS 0.00
CVE-2021-37865 MEDIUM
Mattermost < 6.2.0 - Authenticated Denial of Service via Crafted GIF File Upload
Jan 18, 2022
CVSS 4.3
EPSS 0.01
CVE-2021-37864 LOW
Mattermost < 6.1 - Authenticated Improper Access Control via Archived Channel API
Jan 18, 2022
CVSS 2.6
EPSS 0.00
CVE-2021-37863 LOW
Mattermost < 6.0 - Authenticated Denial of Service via Malicious Post Creation
Dec 17, 2021
CVSS 3.5
EPSS 0.01
CVE-2021-37862 LOW
Mattermost < 6.0 - Email Address Spoofing via Crafted Invitation Token
Dec 17, 2021
CVSS 3.7
EPSS 0.00
CVE-2021-37861 MEDIUM
Mattermost < 6.0.2 - Password Exposure in Audit Logs
Dec 09, 2021
CVSS 5.8
EPSS 0.00
CVE-2021-37860 LOW
Mattermost < 5.38 - Stored Cross-Site Scripting via Clipboard Content
Sep 22, 2021
CVSS 3.7
EPSS 0.00
CVE-2021-37859 HIGH
Mattermost 5.32.0-5.34.5 - Reflected Cross-Site Scripting Bypass in OAuth Flow
Aug 05, 2021
CVSS 7.1
EPSS 0.45
CVE-2020-13891 HIGH
Mattermost Mobile Apps <1.31.2 - Open Redirect
Jun 26, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-14460 MEDIUM
Mattermost Server <5.19.0 - Privilege Escalation
Jun 19, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-14459 HIGH
Mattermost Server < 5.19.0 - Channel Rename Collision with Direct Message
Jun 19, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-14458 HIGH
Mattermost Server <5.19.0 - Info Disclosure
Jun 19, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-14457 MEDIUM
Mattermost Server <5.20.0 - Info Disclosure
Jun 19, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-14456 HIGH
Mattermost Desktop App < 4.4.0 - Origin Validation Error
Jun 19, 2020
CVSS 7.3
EPSS 0.00
CVE-2020-14455 MEDIUM
Mattermost Desktop App < 4.4.0 - Improper Authentication via HTTP Basic Auth Prompt
Jun 19, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-14454 MEDIUM
Mattermost Desktop App < 4.4.0 - Open Redirect via Server Redirection Mishandling
Jun 19, 2020
CVSS 6.1
EPSS 0.00