Mattermost Server vulnerabilities
389 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
389
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH74MEDIUM266LOW34
Vulnerabilities
Page 16 of 20
CVE-2016-11066HIGHCVSS 7.5fixed in 3.2.02020-06-19
CVE-2016-11066 [HIGH] CWE-200 CVE-2016-11066: An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessar
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
nvd
CVE-2016-11063MEDIUMCVSS 6.1fixed in 3.5.12020-06-19
CVE-2016-11063 [MEDIUM] CWE-79 CVE-2016-11063: An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
nvd
CVE-2016-11068MEDIUMCVSS 5.3fixed in 3.2.02020-06-19
CVE-2016-11068 [MEDIUM] CWE-74 CVE-2016-11068: An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via inje
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
nvd
CVE-2019-20887MEDIUMCVSS 4.3fixed in 4.10.6≥ 5.5.0, < 5.5.3+2 more2020-06-19
CVE-2019-20887 [MEDIUM] CWE-862 CVE-2019-20887: An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not hon
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
nvd
CVE-2019-20844MEDIUMCVSS 6.5fixed in 5.9.7≥ 5.15.0, < 5.15.4+3 more2020-06-19
CVE-2019-20844 [MEDIUM] CWE-924 CVE-2019-20844: An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An at
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel.
nvd
CVE-2020-14452MEDIUMCVSS 5.3fixed in 5.21.02020-06-19
CVE-2020-14452 [MEDIUM] CWE-22 CVE-2020-14452: An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTT
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.
nvd
CVE-2017-18899MEDIUMCVSS 5.3fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18899 [MEDIUM] CWE-770 CVE-2017-18899: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
nvd
CVE-2016-11073MEDIUMCVSS 6.1fixed in 3.0.02020-06-19
CVE-2016-11073 [MEDIUM] CWE-79 CVE-2016-11073: An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support sett
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
nvd
CVE-2017-18876MEDIUMCVSS 4.9fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18876 [MEDIUM] CWE-732 CVE-2017-18876: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for f
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
nvd
CVE-2017-18921MEDIUMCVSS 6.1fixed in 3.5.22020-06-19
CVE-2017-18921 [MEDIUM] CWE-79 CVE-2017-18921: An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an
An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.
nvd
CVE-2016-11078MEDIUMCVSS 6.5fixed in 3.0.02020-06-19
CVE-2016-11078 [MEDIUM] CWE-200 CVE-2016-11078: An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.
nvd
CVE-2019-20890MEDIUMCVSS 4.3fixed in 5.7.02020-06-19
CVE-2019-20890 [MEDIUM] CVE-2019-20890: An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discov
An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
nvd
CVE-2019-20878MEDIUMCVSS 4.3fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20878 [MEDIUM] CVE-2019-20878: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.
nvd
CVE-2016-11081MEDIUMCVSS 4.3fixed in 2.2.02020-06-19
CVE-2016-11081 [MEDIUM] CWE-200 CVE-2016-11081: An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to informatio
An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser.
nvd
CVE-2019-20870MEDIUMCVSS 4.3fixed in 5.10.02020-06-19
CVE-2019-20870 [MEDIUM] CWE-20 CVE-2019-20870: An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appe
An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited flag after changing a post's file ID.
nvd
CVE-2017-18878MEDIUMCVSS 4.3fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18878 [MEDIUM] CWE-732 CVE-2017-18878: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
nvd
CVE-2019-20877MEDIUMCVSS 5.3fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20877 [MEDIUM] CVE-2019-20877: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attac
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
nvd
CVE-2017-18881MEDIUMCVSS 6.1fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18881 [MEDIUM] CWE-79 CVE-2017-18881: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a g
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.
nvd
CVE-2017-18882MEDIUMCVSS 6.1fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18882 [MEDIUM] CWE-79 CVE-2017-18882: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenG
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.
nvd
CVE-2019-20866MEDIUMCVSS 5.3fixed in 5.12.02020-06-19
CVE-2019-20866 [MEDIUM] CWE-444 CVE-2019-20866: An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than
An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address in an IP packet header, for obtaining IP address information was mishandled.
nvd