Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mattermost mattermost server 5.18.0 vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2019-20844
An issue exists in Mattermost Server prior to 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel.
Mattermost Mattermost Server
Mattermost Mattermost Server 5.18.0
605
VMScore
CVE-2019-20841
An issue exists in Mattermost Server prior to 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.
Mattermost Mattermost Server
Mattermost Mattermost Server 5.18.0
578
VMScore
CVE-2019-20842
An issue exists in Mattermost Server prior to 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by admins via SearchAllChannels.
Mattermost Mattermost Server
Mattermost Mattermost Server 5.18.0
445
VMScore
CVE-2019-20843
An issue exists in Mattermost Server prior to 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.
Mattermost Mattermost Server
Mattermost Mattermost Server 5.18.0
445
VMScore
CVE-2019-20846
An issue exists in Mattermost Server prior to 5.18.0. It has weak permissions for server-local file storage.
Mattermost Mattermost Server
445
VMScore
CVE-2019-20847
An issue exists in Mattermost Server prior to 5.18.0. An attacker can send a user_typing WebSocket event to any channel.
Mattermost Mattermost Server
445
VMScore
CVE-2019-20845
An issue exists in Mattermost Server prior to 5.18.0. It allows malicious users to cause a denial of service (memory consumption) via a large Slack import.
Mattermost Mattermost Server
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started