Show filters
381 Total Results
Displaying 1-10 of 381
Sort by:
Attacker Value
Unknown
CVE-2025-0503
Disclosure Date: February 14, 2025 (last updated February 15, 2025)
Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
0
Attacker Value
Unknown
CVE-2025-20630
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.
0
Attacker Value
Unknown
CVE-2025-20621
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel.
0
Attacker Value
Unknown
CVE-2025-20072
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
0
Attacker Value
Unknown
CVE-2025-0476
Disclosure Date: January 16, 2025 (last updated January 16, 2025)
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
0
Attacker Value
Unknown
CVE-2025-21083
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown
CVE-2025-20088
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown
CVE-2025-20086
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown
CVE-2025-20036
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
0
Attacker Value
Unknown
CVE-2025-21088
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
0