Mattermost

Mattermost Server

312 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Published 16.01.2025 19:15:29
  • Last modified 01.10.2025 17:54:41

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via cre...

  • EPSS 0.25%
  • Published 15.01.2025 17:15:19
  • Last modified 30.09.2025 15:51:23

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

  • EPSS 0.25%
  • Published 15.01.2025 17:15:19
  • Last modified 01.10.2025 18:20:36

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

  • EPSS 0.19%
  • Published 15.01.2025 16:15:32
  • Last modified 30.09.2025 15:52:59

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafte...

  • EPSS 0.27%
  • Published 09.01.2025 07:15:28
  • Last modified 02.10.2025 17:26:14

Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_...

  • EPSS 0.09%
  • Published 09.01.2025 07:15:28
  • Last modified 02.10.2025 17:25:07

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

  • EPSS 0.08%
  • Published 09.01.2025 07:15:28
  • Last modified 29.09.2025 17:44:58

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

  • EPSS 0.53%
  • Published 16.12.2024 08:15:05
  • Last modified 30.09.2025 15:49:33

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a...

  • EPSS 0.15%
  • Published 16.12.2024 08:15:05
  • Last modified 30.09.2025 15:50:38

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.

  • EPSS 0.06%
  • Published 05.12.2024 16:15:25
  • Last modified 01.10.2025 18:21:08

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.