Show filters
890 Total Results
Displaying 21-30 of 890
Sort by:
Attacker Value
Unknown
CVE-2025-0476
Disclosure Date: January 16, 2025 (last updated January 16, 2025)
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
0
Attacker Value
Unknown
CVE-2025-21083
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown
CVE-2025-20088
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown
CVE-2025-20086
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown
CVE-2025-20036
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown
CVE-2025-21088
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
0
Attacker Value
Unknown
CVE-2024-12877
Disclosure Date: January 11, 2025 (last updated January 12, 2025)
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server that makes remote code execution possible. Please note this was only partially patched in 3.19.3, a fully sufficient patch was not released until 3.19.4. However, another CVE was assigned by another CNA for version 3.19.3 so we will leave this as affecting 3.19.2 and before. We have recommended the vendor use JSON encoding to prevent any further deserialization vulnerabilities from being present.
0
Attacker Value
Unknown
CVE-2025-22449
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.
0
Attacker Value
Unknown
CVE-2025-22445
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.
0
Attacker Value
Unknown
CVE-2025-20033
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_notification type and specific props.
0