An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

Security Advisories for github.com/mattermost/mattermost-server Clear Filters

Moderate
24 days ago

Mattermost has Potential Server Crash due to Unvalidated Import Data GSA_kwCzR0hTQS1oNDY5LTRmY2YtcDIzaM4ABLUR

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
24 days ago

Mattermost Fails to Sanitize File Names GSA_kwCzR0hTQS1wajZmLXJjOTQtZ3c1M84ABLUh

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
25 days ago

Mattermost Fails to Sanitize Path Traversal Sequences GSA_kwCzR0hTQS14NjdjLXY4anItcDI5cs4ABLTm

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
25 days ago

Mattermost Server SSRF Vulnerability via the Agents Plugin GSA_kwCzR0hTQS12cXdoLTVqaGgtdmM5cM4ABLTk

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
25 days ago

Mattermost Fails to Validate File Paths GSA_kwCzR0hTQS1ncTNyLTU4MzMtNTUzMs4ABLTi

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
25 days ago

Mattermost Does Not Sanitize the Team Invite ID GSA_kwCzR0hTQS1xajQ3LXc5ZjItcWc0NM4ABLTl

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
25 days ago

Mattermost Fails to Properly Validate Team Role Modification GSA_kwCzR0hTQS00Mjc2LWNtOGMtNzg4aM4ABLTj

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
25 days ago

Mattermost Fails to Validate Remote Cluster Upload Sessions GSA_kwCzR0hTQS1xNDUzLTYzOGMtaDRtcs4ABLTn

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
25 days ago

Mattermost Lack of Access Control Validation GSA_kwCzR0hTQS1wd3ZyLWdycWctN3ZwMs4ABLTo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
about 2 months ago

Mattermost has Insufficiently Protected Credentials GSA_kwCzR0hTQS00ZndqLTg1OTUtd3AyNc4ABKRo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
about 2 months ago

Mattermost Path Traversal vulnerability GSA_kwCzR0hTQS13dncyLTNqaDQtNGMzOc4ABKRq

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
about 2 months ago

Mattermost Missing Authentication for Critical Function GSA_kwCzR0hTQS03aDM0LTljaHItNThxaM4ABKRa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS13Z3ZwLWpqNHctODhoZs4ABJkw

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS12OGZyLXZ4bXctNm1mNs4ABJkm

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago

Mattermost allows unauthorized channel member management through playbook runs GSA_kwCzR0hTQS1xd3dtLWM1ODItODJyeM4ABJTJ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago

Mattermost allows an unauthorized Guest user access to Playbook GSA_kwCzR0hTQS00NTc4LTZnamgtZjJqbc4ABJTD

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Critical
3 months ago

Mattermost allows authenticated users to write files to arbitrary locations GSA_kwCzR0hTQS1xaDU4LTl2M2otd2NqY84ABJSQ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
3 months ago

Mattermost allows guest users to view information about public teams they are not members of GSA_kwCzR0hTQS1qd2h3LXhmNXYtcWd4Y84ABI-z

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost allows authenticated administrator to execute LDAP search filter injection GSA_kwCzR0hTQS00cjY3LTR4NHAtZnByZ84ABI-v

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
5 months ago

Mattermost Fails to Restrict Certain Operations on System Admins GSA_kwCzR0hTQS0zMjJ2LXZoMmctcXZwds4ABGvR

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
6 months ago

Mattermost allows members with permission to convert public channels to private and convert private to public GSA_kwCzR0hTQS1oNXY5LXh3MmctN2hycc4ABFxA

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
6 months ago

Mattermost Fails to Properly Perform Viewer Role Authorization GSA_kwCzR0hTQS1mcXJxLXhteGotdjQ3eM4ABFpb

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
about 1 year ago

Mattermost did not properly restrict channel creation GSA_kwCzR0hTQS12dnBnLTU1cDctNWg4d84AA-UY

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost/server/v8
Low
over 1 year ago

Mattermost fails to fully validate role changes GSA_kwCzR0hTQS01cXg5LTlmZmotNXI4Zs4AA7VE

go github.com/mattermost/mattermost-server
Moderate
over 1 year ago

Mattermost fails to limit the number of active sessions GSA_kwCzR0hTQS13ajM3LW1wcTkteHJjbc4AA7VH

go github.com/mattermost/mattermost-server
Low
over 1 year ago

Mattermost Server Resource Exhaustion GSA_kwCzR0hTQS1xcWM4LXJ2MzctNzlxNc4AA6BG

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
almost 2 years ago

Mattermost password hash disclosure vulnerability GSA_kwCzR0hTQS1yNjdtLW1mN3YtcXA3as4AA29D

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost/server/v8
Moderate
over 2 years ago

Mattermost vulnerable to information disclosure GSA_kwCzR0hTQS04amhoLTNqZjItcGZ3cs4AAyez

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
Moderate
over 2 years ago

Mattermost vulnerable to cross-site scripting (XSS) GSA_kwCzR0hTQS02M2YyLTY5NTktMnB4as4AAye3

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
Moderate
over 2 years ago

Mattermost fails to properly authentication inviter's permissions to private channel GSA_kwCzR0hTQS05aGo3LXY1NmctcmhmNs4AAyey

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
Moderate
over 2 years ago

Mattermost vulnerable to information disclosure GSA_kwCzR0hTQS0zd3E1LTNmNTYtdjV4Y84AAyex

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server/v6
Moderate
almost 3 years ago

Denial of service in Mattermost GSA_kwCzR0hTQS12NDJmLWhxNzgtOGM1bc4AAwBK

go github.com/mattermost/mattermost-server
Moderate
almost 3 years ago

Denial of service in Mattermost GSA_kwCzR0hTQS01anBoLXdycTctdjloZs4AAwBJ

go github.com/mattermost/mattermost-server
Moderate
over 3 years ago

Uncontrolled Resource Consumption in Mattermost server GSA_kwCzR0hTQS1nd3BmLTk1amMtNjNyds4AArUl

go github.com/mattermost/mattermost-server

Filter by Severity

Filter by Ecosystem

Filter by Package

tensorflow 433 tensorflow-gpu 427 tensorflow-cpu 423 moodle/moodle 418 magento/community-edition 302 Microsoft.ChakraCore 247 org.jenkins-ci.main:jenkins-core 239 typo3/cms 190 com.liferay.portal:release.portal.bom 141 org.apache.tomcat:tomcat 136 com.liferay.portal:release.dxp.bom 125 github.com/mattermost/mattermost/server/v8 124 pimcore/pimcore 120 dolibarr/dolibarr 116 typo3/cms-core 114 Django 108 phpmyadmin/phpmyadmin 107 microweber/microweber 103 drupal/core 103 magento/project-community-edition 102 silverstripe/framework 92 apache-airflow 85 librenms/librenms 83 drupal/drupal 83 thorsten/phpmyfaq 73 Plone 72 com.fasterxml.jackson.core:jackson-databind 69 symfony/symfony 69 github.com/usememos/memos 68 concrete5/concrete5 67 salt 65 ansible 63 apache-superset 61 actionpack 61 shopware/platform 58 org.apache.struts:struts2-core 57 github.com/grafana/grafana 56 craftcms/cms 53 mlflow 53 org.keycloak:keycloak-core 50 github.com/hashicorp/vault 49 org.apache.tomcat.embed:tomcat-embed-core 48 mautic/core 48 nova 48 baserproject/basercms 47 django 46 nokogiri 46 shopware/core 46 github.com/mattermost/mattermost-server/v6 45 github.com/rancher/rancher 45 vyper 44 gradio 44 org.xwiki.platform:xwiki-platform-oldcore 43 rdiffweb 42 org.keycloak:keycloak-services 42 nilsteampassnet/teampass 42 matrix-synapse 42 k8s.io/kubernetes 42 showdoc/showdoc 41 plone 41 org.elasticsearch:elasticsearch 41 mantisbt/mantisbt 41 intelliants/subrion 40 froxlor/froxlor 40 directus 39 picklescan 39 github.com/mattermost/mattermost-server 38 com.thoughtworks.xstream:xstream 37 net.mingsoft:ms-mcms 36 com.jfinal:jfinal 36 snipe/snipe-it 36 moin 35 io.undertow:undertow-core 35 zendframework/zendframework1 34 org.jenkins-ci.plugins:script-security 34 github.com/answerdev/answer 34 parse-server 33 gogs.io/gogs 33 keystone 32 github.com/argoproj/argo-cd/v2 32 opencv-python 31 opencv-contrib-python 31 github.com/hashicorp/nomad 31 shopware/shopware 31 github.com/cilium/cilium 31 github.com/argoproj/argo-cd 31 github.com/docker/docker 31 getgrav/grav 30 github.com/hashicorp/consul 29 rack 29 Pillow 29 next 29 electron 29 contao/core-bundle 29 mediawiki/core 28 org.apache.solr:solr-core 28 pillow 28 prestashop/prestashop 27 centreon/centreon 27 org.opencms:opencms-core 27 openssl-src 26 org.springframework.security:spring-security-core 26 github.com/traefik/traefik/v2 25 vllm 25 org.eclipse.jetty:jetty-server 25 rubygems-update 25 open-webui 25 pocketmine/pocketmine-mp 25 surrealdb 24 magento/core 24 getkirby/cms 24 org.keycloak:keycloak-parent 24 phpoffice/phpexcel 23 org.bouncycastle:bcprov-jdk14 23 org.bouncycastle:bcprov-jdk15on 23 grumpydictator/firefly-iii 23 laravel/framework 23 zendframework/zendframework 23 simplesamlphp/simplesamlphp 23 puppet 23 org.apache.tomcat:tomcat-catalina 23 pyload-ng 23 remdex/livehelperchat 23 Microsoft.AspNetCore.App.Runtime.win-x64 22 DotNetNuke.Core 22 tribalsystems/zenario 22 phpoffice/phpspreadsheet 22 contao/contao 22 @openzeppelin/contracts-upgradeable 22 ckb 22 org.apache.openmeetings:openmeetings-parent 22 activerecord 22 Microsoft.AspNetCore.App.Runtime.win-x86 22 helm.sh/helm/v3 21 github.com/ethereum/go-ethereum 21 @openzeppelin/contracts 21 glance 21 Microsoft.AspNetCore.App.Runtime.win-arm 21 github.com/goharbor/harbor 21 org.apache.nifi:nifi 21 cockpit-hq/cockpit 20 code.gitea.io/gitea 20 aim 20 org.apache.tomcat:tomcat-coyote 20 org.cloudfoundry.identity:cloudfoundry-identity-server 20 wasmtime 20 funadmin/funadmin 20 golang.org/x/net 20 langchain 20 typo3/cms-backend 20 org.xwiki.platform:xwiki-platform-web-templates 20 ethyca-fides 20 Microsoft.AspNetCore.App.Runtime.linux-x64 19 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 19 Microsoft.AspNetCore.App.Runtime.osx-x64 19 github.com/zitadel/zitadel 19 Microsoft.AspNetCore.App.Runtime.linux-arm 19 topthink/framework 19 neutron 19 deno 19 Microsoft.AspNetCore.App.Runtime.linux-arm64 19 Microsoft.AspNetCore.App.Runtime.win-arm64 19 mercurial 18 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 18 genix/cms 18 forkcms/forkcms 18 cobbler 18 com.vaadin:vaadin-bom 18 flowise 18 org.apache.jspwiki:jspwiki-main 18 mindsdb 18 org.apache.inlong:manager-pojo 17 cryptography 17 ezsystems/ezpublish-kernel 17 yetiforce/yetiforce-crm 17 github.com/traefik/traefik/v3 17 calibreweb 17 cakephp/cakephp 17 francoisjacquet/rosariosis 17 opencart/opencart 17 org.springframework:spring-core 17 org.apache.geode:geode-core 17 symfony/security 17 github.com/openfga/openfga 17 notebook 17 OctoPrint 17 openmage/magento-lts 17 org.apache.activemq:activemq-client 16 Microsoft.NetCore.App.Runtime.win-x64 16 transformers 16 rusqlite 16 sequelize 16 Microsoft.NetCore.App.Runtime.win-arm64 16 tinymce 16 org.apache.dubbo:dubbo 16 Microsoft.NetCore.App.Runtime.win-x86 16 org.bouncycastle:bcprov-jdk15 16 Microsoft.NetCore.App.Runtime.win-arm 16 lollms 16 october/system 16

Filter by Repository