CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “mattermost”

362 vulnerabilities found for “mattermost”

Page 1 of 19

CVE-2025-30516
LOW2.0

Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications

mattermost / mattermost_mobile
Physical
Published Apr 14, 2025
Page 1 of 19
CVE-2025-1558
MEDIUM6.5

Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.

mattermost / mattermost_mobile
Network
Published Mar 24, 2025
CVE-2025-20630
MEDIUM6.5

Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.

mattermost / mattermost_mobile
Network
Published Jan 16, 2025
CVE-2025-20072
MEDIUM6.5

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.

mattermost / mattermost_mobile
Network
Published Jan 16, 2025
CVE-2025-0476
MEDIUM4.3

Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment

mattermost / mattermost_mobile
Network
Published Jan 16, 2025
CVE-2025-20036
MEDIUM6.5

Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

mattermost / mattermost_mobile
Network
Published Jan 15, 2025
CVE-2025-21083
MEDIUM6.5

Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

mattermost / mattermost_mobile
Network
Published Jan 15, 2025
CVE-2024-11358
MEDIUM5.7

Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.

mattermost / mattermost_mobile
Local
Published Dec 16, 2024
CVE-2024-45833
MEDIUM4.5

Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..

mattermost / mattermost_mobile
Network
Published Sep 16, 2024
CVE-2024-39767
MEDIUM4.2

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.

mattermost / mattermost_mobile
Network
Published Jul 15, 2024
CVE-2024-32945
LOW2.6

Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.

mattermost / mattermost_mobile
Network
Published Jul 15, 2024
CVE-2024-3872
LOW3.1

Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.

mattermost / mattermost_mobile
Network
Published Apr 16, 2024
CVE-2024-24975
LOW3.5

Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app.

mattermost / mattermost_mobile
Network
Published Mar 15, 2024
CVE-2020-14451
HIGH7.5

An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2020-14449
HIGH7.5

An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2019-20853
CRITICAL9.8

An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that has a remote code execution problem.

mattermost / mattermost_packages
Network
Published Jun 19, 2020
CVE-2019-20850
MEDIUM5.3

An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2019-20852
HIGH7.5

An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2019-20848
HIGH7.5

An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2019-20849
MEDIUM5.3

An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020