Filtered by vendor Mattermost Subscriptions
Filtered by product Mattermost Server Subscriptions
Total 199 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2016-11067 1 Mattermost 1 Mattermost Server 2020-06-24 5.3 Medium
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
CVE-2017-18877 1 Mattermost 1 Mattermost Server 2020-06-24 6.1 Medium
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
CVE-2016-11068 1 Mattermost 1 Mattermost Server 2020-06-24 5.3 Medium
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
CVE-2017-18907 1 Mattermost 1 Mattermost Server 2020-06-24 6.1 Medium
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
CVE-2017-18913 1 Mattermost 1 Mattermost Server 2020-06-24 6.1 Medium
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.
CVE-2017-18921 1 Mattermost 1 Mattermost Server 2020-06-24 6.1 Medium
An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.
CVE-2018-21248 1 Mattermost 1 Mattermost Server 2020-06-24 7.5 High
An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.
CVE-2016-11066 1 Mattermost 1 Mattermost Server 2020-06-24 7.5 High
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
CVE-2018-21249 1 Mattermost 1 Mattermost Server 2020-06-23 3.7 Low
An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing.
CVE-2018-21258 1 Mattermost 1 Mattermost Server 2020-06-23 7.5 High
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.
CVE-2016-11084 1 Mattermost 1 Mattermost Server 2020-06-23 6.1 Medium
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
CVE-2017-18917 1 Mattermost 1 Mattermost Server 2020-06-23 7.5 High
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.
CVE-2017-18918 1 Mattermost 1 Mattermost Server 2020-06-23 4.9 Medium
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.
CVE-2017-18920 1 Mattermost 1 Mattermost Server 2020-06-23 9.8 Critical
An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.
CVE-2016-11076 1 Mattermost 1 Mattermost Server 2020-06-23 5.3 Medium
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
CVE-2019-20854 1 Mattermost 1 Mattermost Server 2020-06-23 7.5 High
An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message.
CVE-2019-20862 1 Mattermost 1 Mattermost Server 2020-06-23 7.5 High
An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands.
CVE-2019-20868 1 Mattermost 1 Mattermost Server 2020-06-23 7.5 High
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
CVE-2019-20870 1 Mattermost 1 Mattermost Server 2020-06-23 4.3 Medium
An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited flag after changing a post's file ID.
CVE-2019-20871 1 Mattermost 1 Mattermost Server 2020-06-23 7.5 High
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking.