CVE-2026-22880
- EPSS 0.12%
- Veröffentlicht 21.05.2026 08:22:00
- Zuletzt bearbeitet 06.08.2026 15:42:06
Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a leg...
CVE-2025-59480
- EPSS 0.14%
- Veröffentlicht 13.11.2025 17:32:04
- Zuletzt bearbeitet 21.01.2026 19:37:37
Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses
CVE-2025-30516
- EPSS 0.26%
- Veröffentlicht 14.04.2025 06:56:22
- Zuletzt bearbeitet 24.09.2025 14:57:30
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifica...
CVE-2025-1558
- EPSS 0.37%
- Veröffentlicht 24.03.2025 15:15:16
- Zuletzt bearbeitet 25.09.2025 19:14:35
Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.
CVE-2025-20630
- EPSS 0.61%
- Veröffentlicht 16.01.2025 19:15:30
- Zuletzt bearbeitet 24.09.2025 16:42:32
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.
CVE-2025-20072
- EPSS 0.53%
- Veröffentlicht 16.01.2025 18:15:28
- Zuletzt bearbeitet 24.09.2025 16:46:59
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
CVE-2025-0476
- EPSS 0.37%
- Veröffentlicht 16.01.2025 00:15:25
- Zuletzt bearbeitet 24.09.2025 16:47:36
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
CVE-2025-21083
- EPSS 0.52%
- Veröffentlicht 15.01.2025 17:15:19
- Zuletzt bearbeitet 25.09.2025 19:14:15
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
CVE-2025-20036
- EPSS 0.52%
- Veröffentlicht 15.01.2025 17:15:18
- Zuletzt bearbeitet 25.09.2025 19:14:06
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
CVE-2024-11358
- EPSS 0.12%
- Veröffentlicht 16.12.2024 17:15:07
- Zuletzt bearbeitet 24.09.2025 19:39:33
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.