Show filters
381 Total Results
Displaying 1-10 of 381
Sort by:
Attacker Value
Unknown

CVE-2025-0503

Disclosure Date: February 14, 2025 (last updated February 15, 2025)
Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
0
Attacker Value
Unknown

CVE-2025-20630

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.
0
Attacker Value
Unknown

CVE-2025-20621

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel.
0
Attacker Value
Unknown

CVE-2025-20072

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
0
Attacker Value
Unknown

CVE-2025-0476

Disclosure Date: January 16, 2025 (last updated January 16, 2025)
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
0
Attacker Value
Unknown

CVE-2025-21083

Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown

CVE-2025-20088

Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown

CVE-2025-20086

Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown

CVE-2025-20036

Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown

CVE-2025-21088

Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
0