Open Source Vulnerabilities
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server vulnerable to XSS via an uploaded file
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server vulnerable to XSS via an uploaded file
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server has Insufficient Session Expiration when used as an OAuth 2.0 service provider
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server has Insufficient Session Expiration when used as an OAuth 2.0 service provider
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server password reset email requests can be sent to attacker-provided email addresses
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server password reset email requests can be sent to attacker-provided email addresses
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server vulnerable to XSS through channel headers
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server vulnerable to XSS through channel headers
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable CSV Injection
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable CSV Injection
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server exposes private team invite ID
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server exposes private team invite ID
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server vulnerable to CSRF if CORS is enabled
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server vulnerable to CSRF if CORS is enabled
github.com/mattermost/mattermost-server
Mattermost Server SAML implementation does not require encryption or signature verification as default
github.com/mattermost/mattermost-server
Mattermost Server SAML implementation does not require encryption or signature verification as default
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server does not neutralize HTML content in an Email template field
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server does not neutralize HTML content in an Email template field
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server allows attackers to create buttons that can launch API requests
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server allows attackers to create buttons that can launch API requests
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to SQL Injection when executing multiple POST requests
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to SQL Injection when executing multiple POST requests
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server allows attackers to log sensitive information via DEBUG REST API logging endpoint
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server allows attackers to log sensitive information via DEBUG REST API logging endpoint
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server mishandles redirect denial action
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server mishandles redirect denial action
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server does not safeguard against phishing via error page links
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server does not safeguard against phishing via error page links
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through display name field
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through display name field
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to DoS through maliciously crafted posts
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to DoS through maliciously crafted posts
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server has intermittent Authorization bypass for resource-owners
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server has intermittent Authorization bypass for resource-owners
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server exposes sensitive user status information via REST API version 4 endpoint
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server exposes sensitive user status information via REST API version 4 endpoint
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server does not properly restrict use of slash commands
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server does not properly restrict use of slash commands
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server exposes OAuth personal access tokens to attackers
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server exposes OAuth personal access tokens to attackers
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to webhook and slash command manipulation
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to webhook and slash command manipulation
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server does not prevent System Admin from arbitrary file creation
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server does not prevent System Admin from arbitrary file creation
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through author_link field in Slack attachments
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through author_link field in Slack attachments
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server allows users with a session ID to revoke another users' session
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server allows users with a session ID to revoke another users' session
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server has low entropy for authorization data as an OAuth 2.0 Service Provider
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server has low entropy for authorization data as an OAuth 2.0 Service Provider
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to channel invisibility DoS via misformatted post
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to channel invisibility DoS via misformatted post
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server exposes team creator's e-mail address to other members
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server exposes team creator's e-mail address to other members
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS attacks against an OAuth 2.0 allow/deny page
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS attacks against an OAuth 2.0 allow/deny page
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to Path Traversal when files are stored locally
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to Path Traversal when files are stored locally
github.com/mattermost/mattermost-server
Mattermost Server allows XSS via redirect URL
github.com/mattermost/mattermost-server
Mattermost Server allows XSS via redirect URL
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through crafted links
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS through crafted links
github.com/mattermost/mattermost-server
Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
github.com/mattermost/mattermost-server
Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
github.com/mattermost/mattermost-server
Mattermost Server allows XSS via CSRF
github.com/mattermost/mattermost-server
Mattermost Server allows XSS via CSRF
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server's OAuth 2.0 service is vulnerable to attack through Missing Authorization
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server's OAuth 2.0 service is vulnerable to attack through Missing Authorization
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to Directory Traversal by System Admins
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to Directory Traversal by System Admins
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server
Mattermost Server vulnerable to Denial of Service through `@` character prefix inserted into JavaScript field names
github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server/ github.com/mattermost/mattermost-server
Mattermost Server vulnerable to Denial of Service through `@` character prefix inserted into JavaScript field names
github.com/mattermost/mattermost-server
Mattermost Server exposes information stored by a web browser
github.com/mattermost/mattermost-server
Mattermost Server exposes information stored by a web browser
github.com/mattermost/mattermost-server
Mattermost Server exposes account details to any Team Administrator
github.com/mattermost/mattermost-server
Mattermost Server exposes account details to any Team Administrator
github.com/mattermost/mattermost-server
Mattermost Server allows System Admin to modify LDAP account names and email addresses
github.com/mattermost/mattermost-server
Mattermost Server allows System Admin to modify LDAP account names and email addresses
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to Uncontrolled Resource Consumption
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to Uncontrolled Resource Consumption
github.com/mattermost/mattermost-server
Mattermost Server: initial_load API exposes unnecessary information
github.com/mattermost/mattermost-server
Mattermost Server: initial_load API exposes unnecessary information
github.com/mattermost/mattermost-server
Mattermost Server does not enforce rate limits on password change attempts
github.com/mattermost/mattermost-server
Mattermost Server does not enforce rate limits on password change attempts
github.com/mattermost/mattermost-server
Mattermost Server's Session ID and Session Token are potentially compromised
github.com/mattermost/mattermost-server
Mattermost Server's Session ID and Session Token are potentially compromised
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS via a Legal or Support setting
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to XSS via a Legal or Support setting
github.com/mattermost/mattermost-server
Mattermost Server: Insufficient Password-Reset Link Invalidation
github.com/mattermost/mattermost-server
Mattermost Server: Insufficient Password-Reset Link Invalidation
github.com/mattermost/mattermost-server
Mattermost Server exposes sensitive information about team URLs via an API
github.com/mattermost/mattermost-server
Mattermost Server exposes sensitive information about team URLs via an API
github.com/mattermost/mattermost-server
Mattermost Server does not check if cookies are used over SSL
github.com/mattermost/mattermost-server
Mattermost Server does not check if cookies are used over SSL
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to Code Injection through its LDAP fields
github.com/mattermost/mattermost-server
Mattermost Server is vulnerable to Code Injection through its LDAP fields
