Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mattermost mattermost server vulnerabilities and exploits
(subscribe to this query)
516
VMScore
CVE-2022-1385
Mattermost 6.4.x and previous versions fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.
Mattermost Mattermost Server
516
VMScore
CVE-2021-37862
Mattermost 6.0 and previous versions fails to sufficiently validate the email address during registration, which allows malicious users to trick users into signing up using attacker-controlled email addresses via crafted invitation token.
Mattermost Mattermost Server
516
VMScore
CVE-2017-18897
An issue exists in Mattermost Server prior to 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.2.0
516
VMScore
CVE-2017-18891
An issue exists in Mattermost Server prior to 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.2.0
516
VMScore
CVE-2020-14454
An issue exists in Mattermost Desktop App prior to 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
Mattermost Mattermost Desktop
490
VMScore
CVE-2017-18874
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
490
VMScore
CVE-2017-18884
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It allows malicious users to gain privileges by using a registered OAuth application with personal access tokens.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
490
VMScore
CVE-2017-18894
An issue exists in Mattermost Server prior to 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.2.0
490
VMScore
CVE-2019-20876
An issue exists in Mattermost Server prior to 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
Mattermost Mattermost Server
Mattermost Mattermost Server 5.9.0
454
VMScore
CVE-2017-18903
An issue exists in Mattermost Server prior to 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
Mattermost Mattermost Server
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »