CVE-2025-30516
- EPSS 0.03%
- Veröffentlicht 14.04.2025 06:56:22
- Zuletzt bearbeitet 24.09.2025 14:57:30
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifica...
CVE-2025-1558
- EPSS 0.11%
- Veröffentlicht 24.03.2025 15:15:16
- Zuletzt bearbeitet 25.09.2025 19:14:35
Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.
CVE-2025-20630
- EPSS 0.15%
- Veröffentlicht 16.01.2025 19:15:30
- Zuletzt bearbeitet 24.09.2025 16:42:32
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.
CVE-2025-20072
- EPSS 0.12%
- Veröffentlicht 16.01.2025 18:15:28
- Zuletzt bearbeitet 24.09.2025 16:46:59
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
CVE-2025-0476
- EPSS 0.31%
- Veröffentlicht 16.01.2025 00:15:25
- Zuletzt bearbeitet 24.09.2025 16:47:36
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
CVE-2025-21083
- EPSS 0.15%
- Veröffentlicht 15.01.2025 17:15:19
- Zuletzt bearbeitet 25.09.2025 19:14:15
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
CVE-2025-20036
- EPSS 0.15%
- Veröffentlicht 15.01.2025 17:15:18
- Zuletzt bearbeitet 25.09.2025 19:14:06
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
CVE-2024-11358
- EPSS 0.02%
- Veröffentlicht 16.12.2024 17:15:07
- Zuletzt bearbeitet 24.09.2025 19:39:33
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.
CVE-2024-45833
- EPSS 0.1%
- Veröffentlicht 16.09.2024 07:15:03
- Zuletzt bearbeitet 23.09.2024 13:43:42
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard...
CVE-2024-39767
- EPSS 0.13%
- Veröffentlicht 15.07.2024 09:15:02
- Zuletzt bearbeitet 21.11.2024 09:28:20
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server UR...