All vulnerabilities
647 / 647
Sort
7.5
CVE-2025-25279DEB
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail…
2025-01-01Pre-auth
EPSS20.8%
pct 97
6.1
CVE-2021-37859DEB
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled insta…
2021-01-01Pre-auth
EPSS3.3%
pct 86
9.8
CVE-2019-20853CVE
An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet ac…
2019-01-01Pre-auth
EPSS2.2%
pct 80
8.8
CVE-2019-20861DEB
An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute …
2019-01-01Pre-auth
EPSS1.7%
pct 73
9.8
CVE-2019-20856DEB
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib inject…
2019-01-01Pre-auth
EPSS1.4%
pct 69
9.8
CVE-2017-18912DEB
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attac…
2017-01-01Pre-auth
EPSS1.4%
pct 68
9.1
CVE-2019-20851CVE
An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory …
2019-01-01Pre-auth
EPSS1.4%
pct 68
7.5
CVE-2019-20854DEB
An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause…
2019-01-01Pre-auth
EPSS1.3%
pct 67
9.8
CVE-2017-18900DEB
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV inj…
2017-01-01Pre-auth
EPSS1.3%
pct 66
9.8
CVE-2016-11064DEB
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as co…
2016-01-01Pre-auth
EPSS1.3%
pct 66
5.3
CVE-2020-14452DEB
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal vi…
2020-01-01Pre-auth
EPSS1.3%
pct 66
9.8
CVE-2017-18920DEB
An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follo…
2017-01-01Pre-auth
EPSS1.2%
pct 65
6.5
CVE-2017-18874DEB
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage …
2017-01-01
EPSS1.2%
pct 65
7.5
CVE-2018-21248DEB
An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superflu…
2018-01-01Pre-auth
EPSS1.2%
pct 65
9.8
CVE-2018-21251DEB
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypas…
2018-01-01Pre-auth
EPSS1.2%
pct 64
9.8
CVE-2017-18915DEB
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of…
2017-01-01Pre-auth
EPSS1.2%
pct 63
9.8
CVE-2017-18908DEB
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset …
2017-01-01Pre-auth
EPSS1.2%
pct 63
9.8
CVE-2017-18885DEB
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attacker…
2017-01-01Pre-auth
EPSS1.2%
pct 63
9.8
CVE-2016-11074DEB
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reuse…
2016-01-01Pre-auth
EPSS1.2%
pct 63
6.5
CVE-2020-14455DEB
An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authen…
2020-01-01Pre-auth
EPSS1.2%
pct 63
7.5
CVE-2019-20859DEB
An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypasse…
2019-01-01Pre-auth
EPSS1.2%
pct 63
7.5
CVE-2019-20874DEB
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows …
2019-01-01Pre-auth
EPSS1.2%
pct 63
7.5
CVE-2019-20855DEB
An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allow…
2019-01-01Pre-auth
EPSS1.2%
pct 63
7.5
CVE-2018-21258DEB
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial …
2018-01-01Pre-auth
EPSS1.2%
pct 62
7.5
CVE-2020-14458DEB
An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private chan…
2020-01-01Pre-auth
EPSS1.1%
pct 62
7.5
CVE-2016-11066DEB
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnec…
2016-01-01Pre-auth
EPSS1.1%
pct 62
9.1
CVE-2017-18883DEB
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an…
2017-01-01Pre-auth
EPSS1.1%
pct 62
7.5
CVE-2020-14451CVE
An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sig…
2020-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2019-20852CVE
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked f…
2019-01-01Pre-auth
EPSS1.1%
pct 61
8.8
CVE-2018-21264DEB
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce…
2018-01-01
EPSS1.1%
pct 61
7.5
CVE-2020-14450DEB
An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attack…
2020-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2020-14448DEB
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies al…
2020-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2020-14447DEB
An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attack…
2020-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2019-20888DEB
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows at…
2019-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2019-20880DEB
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows …
2019-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2019-20871DEB
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdo…
2019-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2019-20858DEB
An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a deni…
2019-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2019-20857DEB
An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a deni…
2019-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2019-20845DEB
An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a deni…
2019-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2018-21262DEB
An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denia…
2018-01-01Pre-auth
EPSS1.1%
pct 61
Select a vulnerability on the left to open the preview.