Mattermost

Mattermost Server

473 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 28.07.2026 13:58:31
  • Zuletzt bearbeitet 29.07.2026 15:06:39

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory fr...

  • EPSS 0.24%
  • Veröffentlicht 27.07.2026 14:15:25
  • Zuletzt bearbeitet 03.08.2026 15:23:50

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of servic...

  • EPSS 0.22%
  • Veröffentlicht 27.07.2026 14:13:29
  • Zuletzt bearbeitet 03.08.2026 15:24:46

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to...

  • EPSS 0.15%
  • Veröffentlicht 13.07.2026 10:53:15
  • Zuletzt bearbeitet 13.07.2026 20:39:12

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric setting...

  • EPSS 0.15%
  • Veröffentlicht 13.07.2026 10:51:34
  • Zuletzt bearbeitet 13.07.2026 20:38:36

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share acces...

  • EPSS 0.16%
  • Veröffentlicht 13.07.2026 10:47:33
  • Zuletzt bearbeitet 13.07.2026 20:38:00

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate config...

  • EPSS 0.14%
  • Veröffentlicht 13.07.2026 08:17:36
  • Zuletzt bearbeitet 13.07.2026 20:53:34

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via ...

  • EPSS 0.24%
  • Veröffentlicht 13.07.2026 08:13:02
  • Zuletzt bearbeitet 13.07.2026 21:42:01

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via...

  • EPSS 0.18%
  • Veröffentlicht 13.07.2026 08:09:58
  • Zuletzt bearbeitet 13.07.2026 21:42:24

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel ...

  • EPSS 0.17%
  • Veröffentlicht 13.07.2026 08:05:42
  • Zuletzt bearbeitet 14.07.2026 13:19:08

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member...