Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mattermost mattermost server vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2022-2401
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and previous versions allows team members to access some sensitive information by directly accessing the APIs.
Mattermost Mattermost Server 6.6.0
Mattermost Mattermost Server 6.7.0
Mattermost Mattermost Server
Mattermost Mattermost Server 6.6.1
6.5
CVSSv3
CVE-2022-1982
Uncontrolled resource consumption in Mattermost version 6.6.0 and previous versions allows an authenticated malicious user to crash the server via a crafted SVG attachment on a post.
Mattermost Mattermost Server 6.6.0
Mattermost Mattermost Server 6.5.0
Mattermost Mattermost Server
5.3
CVSSv3
CVE-2023-1777
Mattermost allows an malicious user to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
Mattermost Mattermost Server 7.8.0
Mattermost Mattermost Server 7.7.1
Mattermost Mattermost Server
5.3
CVSSv3
CVE-2017-18873
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It allows malicious users to cause a denial of service (channel invisibility) via a misformatted post.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
4.9
CVSSv3
CVE-2017-18875
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
6.1
CVSSv3
CVE-2017-18877
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
4.3
CVSSv3
CVE-2017-18878
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
6.1
CVSSv3
CVE-2017-18881
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
9.1
CVSSv3
CVE-2017-18883
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
9.8
CVSSv3
CVE-2017-18885
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It allows malicious users to gain privileges by accessing unintended API endpoints on a user's behalf.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »