← Back

Mattermost Mobile

mattermost_mobile

Vendor: Mattermost • 20 CVEs

CVEs (20)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Nov 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via...Show more
Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responsesShow less
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Apr 14, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content...Show more
Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notificationsShow less
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Mar 24, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jan 16, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a...Show more
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.Show less
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jan 16, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jan 16, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted att...Show more
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachmentShow less
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jan 15, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jan 15, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Dec 16, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Sep 16, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Sw...Show more
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..Show less
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jul 15, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another serve...Show more
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.Show less
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jul 15, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro def...Show more
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.Show less
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Apr 16, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long mali...Show more
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link. Show less
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Mar 15, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code blo...Show more
Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app. Show less
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jun 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jun 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.