<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Mattermost (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/mattermost.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mattermost-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Mattermost (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-6957 – Mattermost Plugins versions &lt;=1.1.5 fail to sanitize filenames received from fed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6957</guid>
    <pubDate>Wed, 27 May 2026 15:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6957</strong></p>
  <p>Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary locations within the target server's filestore via a malicious filename delivered through the shared-channel attachment sync protocol. Mattermost Advis…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5740 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5740</guid>
    <pubDate>Fri, 22 May 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5740</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unauthenticated remote attacker to crash the server process and cause a full service outage for all users via a crafted binary WebSocket message sent to the public WebSocket endpoint.. Mattermost Advisory…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4858 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4858</guid>
    <pubDate>Thu, 21 May 2026 09:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4858</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user  to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6347 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6347</guid>
    <pubDate>Mon, 18 May 2026 09:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6347</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server credentials via the plaintext values present in the exported plugin configuration.. Mattermost Advisory ID: MMSA-2026-00605</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6346 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6346</guid>
    <pubDate>Mon, 18 May 2026 09:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6346</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermost System Admin or any party with access to a support packet to obtain sensitive credentials in plaintext via downloading a support packet from the System Console.. Mattermost Advisory ID: MMSA-2026-0…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3524 – Mattermost Plugin Legal Hold versions &lt;=1.1.4 fail to halt request processing af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3524</guid>
    <pubDate>Mon, 06 Apr 2026 13:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3524</strong></p>
  <p>Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-00621</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3108 – Mattermost versions 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10, 11.4.x &lt;= 11.4.0, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3108</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3108</strong></p>
  <p>Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences that enable screen manipulation, fake prompts, and clipboard hijacking.. Mattermost Advisory ID: M…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-150</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2476 – Mattermost Plugins versions &lt;=2.0.3.0 fail to properly mask sensitive configurat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2476</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2476</strong></p>
  <p>Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24458 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24458</guid>
    <pubDate>Mon, 16 Mar 2026 14:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24458</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Mattermost Advisory ID: MMSA-2026-00587</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1046 – Mattermost Desktop App versions &lt;=6.0 6.2.0 5.2.13.0 fail to validate help links...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1046</guid>
    <pubDate>Mon, 16 Feb 2026 13:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1046</strong></p>
  <p>Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-939</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13523 – Mattermost Confluence plugin version &lt;1.7.0 fails to properly escape user-contro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13523</guid>
    <pubDate>Fri, 06 Feb 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13523</strong></p>
  <p>Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermos…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14273 – Mattermost versions 11.1.x &lt;= 11.1.0, 11.0.x &lt;= 11.0.5, 10.12.x &lt;= 10.12.3, 10.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14273</guid>
    <pubDate>Mon, 22 Dec 2025 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14273</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST requests to the Jira server via crafted plugi…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12421 – Mattermost versions 11.0.x &lt;= 11.0.2, 10.12.x &lt;= 10.12.1, 10.11.x &lt;= 10.11.4, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12421</guid>
    <pubDate>Thu, 27 Nov 2025 18:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12421</strong></p>
  <p>Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12419 – Mattermost versions 10.12.x &lt;= 10.12.1, 10.11.x &lt;= 10.11.4, 10.5.x &lt;= 10.5.12, 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12419</guid>
    <pubDate>Thu, 27 Nov 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12419</strong></p>
  <p>Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow. This requires email verification to be disabled (d…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58075 – Mattermost versions 10.11.x &lt;= 10.11.1, 10.10.x &lt;= 10.10.2, 10.5.x &lt;= 10.5.10 fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58075</guid>
    <pubDate>Thu, 16 Oct 2025 09:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58075</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58073 – Mattermost versions 10.11.x &lt;= 10.11.1, 10.10.x &lt;= 10.10.2, 10.5.x &lt;= 10.5.10 fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58073</guid>
    <pubDate>Thu, 16 Oct 2025 09:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58073</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9079 – Mattermost versions 10.8.x &lt;= 10.8.3, 10.5.x &lt;= 10.5.8, 9.11.x &lt;= 9.11.17, 10.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9079</guid>
    <pubDate>Fri, 19 Sep 2025 20:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9079</strong></p>
  <p>Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows admin users to execute arbitrary code via malicious plugin upload to prepackaged plugins directory</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9072 – Mattermost versions 10.10.x &lt;= 10.10.1, 10.5.x &lt;= 10.5.9, 10.9.x &lt;= 10.9.4 fail ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9072</guid>
    <pubDate>Mon, 15 Sep 2025 11:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9072</strong></p>
  <p>Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54525 – Mattermost Confluence Plugin version &lt;1.5.0 fails to handle unexpected request b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54525</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54525</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54478 – Mattermost Confluence Plugin version &lt;1.5.0 fails to enforce authentication of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54478</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54478</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52931 – Mattermost Confluence Plugin version &lt;1.5.0 fails to handle unexpected request b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52931</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52931</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-44004 – Mattermost Confluence Plugin version &lt;1.5.0 fails to check the authorization of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44004</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-44004</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-4981 – Mattermost versions 10.5.x &lt;= 10.5.5, 9.11.x &lt;= 9.11.15, 10.8.x &lt;= 10.8.0, 10.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4981</guid>
    <pubDate>Fri, 20 Jun 2025 11:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-4981</strong></p>
  <p>Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25068 – Mattermost versions 10.4.x &lt;= 10.4.2, 10.3.x &lt;= 10.3.3, 9.11.x &lt;= 9.11.8, 10.5.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25068</guid>
    <pubDate>Fri, 21 Mar 2025 09:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25068</strong></p>
  <p>Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25279 – Mattermost versions 10.4.x &lt;= 10.4.1, 9.11.x &lt;= 9.11.7, 10.3.x &lt;= 10.3.2, 10.2.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25279</guid>
    <pubDate>Mon, 24 Feb 2025 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25279</strong></p>
  <p>Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24490 – Mattermost versions 10.4.x &lt;= 10.4.1, 9.11.x &lt;= 9.11.7, 10.3.x &lt;= 10.3.2, 10.2.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24490</guid>
    <pubDate>Mon, 24 Feb 2025 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24490</strong></p>
  <p>Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reordering specially crafted boards categories.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-20051 – Mattermost versions 10.4.x &lt;= 10.4.1, 9.11.x &lt;= 9.11.7, 10.3.x &lt;= 10.3.2, 10.2.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20051</guid>
    <pubDate>Mon, 24 Feb 2025 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-20051</strong></p>
  <p>Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially crafted block in Boards.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11599 – Mattermost versions 10.0.x &lt;= 10.0.1, 10.1.x &lt;= 10.1.1, 9.11.x &lt;= 9.11.3, 9.5.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11599</guid>
    <pubDate>Thu, 28 Nov 2024 10:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11599</strong></p>
  <p>Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39777 – Mattermost versions 9.9.x &lt;= 9.9.0, 9.5.x &lt;= 9.5.6, 9.7.x &lt;= 9.7.5 and 9.8.x &lt;= ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39777</guid>
    <pubDate>Thu, 01 Aug 2024 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39777</strong></p>
  <p>Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39274 – Mattermost versions 9.9.x &lt;= 9.9.0, 9.5.x &lt;= 9.5.6, 9.7.x &lt;= 9.7.5 and 9.8.x &lt;= ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39274</guid>
    <pubDate>Thu, 01 Aug 2024 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39274</strong></p>
  <p>Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote to add users to arbitrary teams and channels</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36492 – Mattermost versions 9.9.x &lt;= 9.9.0, 9.5.x &lt;= 9.5.6, 9.7.x &lt;= 9.7.5, 9.8.x &lt;= 9.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36492</guid>
    <pubDate>Thu, 01 Aug 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36492</strong></p>
  <p>Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39830 – Mattermost versions 9.8.x &lt;= 9.8.0, 9.7.x &lt;= 9.7.4, 9.6.x &lt;= 9.6.2 and 9.5.x &lt;= ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39830</guid>
    <pubDate>Wed, 03 Jul 2024 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39830</strong></p>
  <p>Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster token via a timing attack during remote cluster token comparison.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2450 – Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2450</guid>
    <pubDate>Fri, 15 Mar 2024 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2450</strong></p>
  <p>Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5356 – Incorrect authorization checks in GitLab CE/EE from all versions starting from 8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5356</guid>
    <pubDate>Fri, 12 Jan 2024 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5356</strong></p>
  <p>Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7114 – Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7114</guid>
    <pubDate>Fri, 29 Dec 2023 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7114</strong></p>
  <p>Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45316 – Mattermost fails to validate if a relative path is passed in /plugins/playbooks/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45316</guid>
    <pubDate>Tue, 12 Dec 2023 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45316</strong></p>
  <p>Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6458 – Mattermost webapp fails to validate route parameters in/&lt;TEAM_NAME&gt;/channels/&lt;CH...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6458</guid>
    <pubDate>Wed, 06 Dec 2023 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6458</strong></p>
  <p>Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3615 – Mattermost iOS app fails to properly validate the server certificate while initi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3615</guid>
    <pubDate>Mon, 17 Jul 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3615</strong></p>
  <p>Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-1831 – Mattermost fails to redact from audit logs the user password during user creatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1831</guid>
    <pubDate>Mon, 17 Apr 2023 15:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-1831</strong></p>
  <p>Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-1776 – Boards in Mattermost allows an attacker to upload a malicious SVG image file as ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1776</guid>
    <pubDate>Fri, 31 Mar 2023 12:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-1776</strong></p>
  <p>Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27264 – A missing permissions check in Mattermost Playbooks in Mattermost allows an atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27264</guid>
    <pubDate>Mon, 27 Feb 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27264</strong></p>
  <p>A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37859 – Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37859</guid>
    <pubDate>Thu, 05 Aug 2021 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37859</strong></p>
  <p>Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26290 – Dex is a federated OpenID Connect provider written in Go. In Dex before version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26290</guid>
    <pubDate>Mon, 28 Dec 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26290</strong></p>
  <p>Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the underlying Go library. The vulnerabilities have been addressed in version 2.27.0 by using the xml-roundtrip-validator from M…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26276 – Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26276</guid>
    <pubDate>Thu, 17 Dec 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26276</strong></p>
  <p>Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unverified logins from a SAML IdP. Users that configure Fleet with SSO login may be vulnerable to this issue. This issue is patched in 3.5.1. The fix was made usin…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13891 – An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13891</guid>
    <pubDate>Fri, 26 Jun 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13891</strong></p>
  <p>An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, aka MMSA-2020-0022.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18920 – An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18920</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18920</strong></p>
  <p>An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18917 – An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Wea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18917</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18917</strong></p>
  <p>An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18915 – An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Aft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18915</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18915</strong></p>
  <p>An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18908 – An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18908</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18908</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18906 – An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18906</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18906</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-11074 – An issue was discovered in Mattermost Server before 3.0.0. A password-reset link...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-11074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-11074</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-11074</strong></p>
  <p>An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-11074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-11069 – An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-11069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-11069</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-11069</strong></p>
  <p>An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-11069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-11066 – An issue was discovered in Mattermost Server before 3.2.0. The initial_load API ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-11066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-11066</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-11066</strong></p>
  <p>An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-11066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-11064 – An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-11064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-11064</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-11064</strong></p>
  <p>An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-11064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-9548 – An issue was discovered in Mattermost Server before 1.2.0. It allows attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-9548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-9548</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-9548</strong></p>
  <p>An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-9548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18912 – An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18912</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18912</strong></p>
  <p>An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18911 – An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18911</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18911</strong></p>
  <p>An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18909 – An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Enc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18909</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18909</strong></p>
  <p>An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18903 – An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18903</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18903</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18900 – An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18900</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18900</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18894 – An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, whe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18894</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18894</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18888 – An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18888</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18888</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18886 – An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18886</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18886</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18885 – An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18885</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18885</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18884 – An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18884</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18884</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-18883 – An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, whe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18883</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-18883</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-331</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21264 – An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21264</guid>
    <pubDate>Fri, 19 Jun 2020 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21264</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20888 – An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20888</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20888</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20886 – An issue was discovered in Mattermost Server before 5.8.0. The first user is som...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20886</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20886</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20885 – An issue was discovered in Mattermost Server before 5.8.0. It does not always ge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20885</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20885</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20881 – An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20881</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20881</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20880 – An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20880</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20880</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21263 – An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21263</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21263</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21262 – An issue was discovered in Mattermost Server before 4.7.3. It allows attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21262</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21262</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21258 – An issue was discovered in Mattermost Server before 5.1. It allows attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21258</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21258</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-21251 – An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21251</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-21251</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21248 – An issue was discovered in Mattermost Server before 5.4.0. It mishandles possess...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21248</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21248</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18871 – An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18871</guid>
    <pubDate>Fri, 19 Jun 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18871</strong></p>
  <p>An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20874 – An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20874</guid>
    <pubDate>Fri, 19 Jun 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20874</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20871 – An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20871</guid>
    <pubDate>Fri, 19 Jun 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20871</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20868 – An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20868</guid>
    <pubDate>Fri, 19 Jun 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20868</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20865 – An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20865</guid>
    <pubDate>Fri, 19 Jun 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20865</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20864 – An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20864</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20864</strong></p>
  <p>An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermost account to a different person's GitHub account.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20863 – An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook cre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20863</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20863</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20862 – An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20862</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20862</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20861 – An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20861</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20861</strong></p>
  <p>An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20859 – An issue was discovered in Mattermost Server before 5.15.0. Login access control...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20859</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20859</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20858 – An issue was discovered in Mattermost Server before 5.15.0. It allows attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20858</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20858</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20857 – An issue was discovered in Mattermost Server before 5.16.0. It allows attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20857</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20857</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown renderer hang) via many backtick characters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-20856 – An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20856</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-20856</strong></p>
  <p>An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20855 – An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20855</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20855</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20854 – An issue was discovered in Mattermost Server before 5.17.0. It allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20854</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20854</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-20853 – An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20853</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-20853</strong></p>
  <p>An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that has a remote code execution problem.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20852 – An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20852</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20852</strong></p>
  <p>An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-20851 – An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20851</guid>
    <pubDate>Fri, 19 Jun 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-20851</strong></p>
  <p>An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14459 – An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14459</guid>
    <pubDate>Fri, 19 Jun 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14459</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020-0002.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14458 – An issue was discovered in Mattermost Server before 5.19.0. Attackers can discov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14458</guid>
    <pubDate>Fri, 19 Jun 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14458</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-0004.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14456 – An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14456</guid>
    <pubDate>Fri, 19 Jun 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14456</strong></p>
  <p>An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14453 – An issue was discovered in Mattermost Server before 5.21.0. Socket read operatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14453</guid>
    <pubDate>Fri, 19 Jun 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14453</strong></p>
  <p>An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14451 – An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14451</guid>
    <pubDate>Fri, 19 Jun 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14451</strong></p>
  <p>An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-459</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14451">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
