VendorsMattermostmattermost_mobileall versions
Vulnerabilities

Mattermost Mattermost Mobile

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2019-20852
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2020-14451
An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2020-14449
An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20848
An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.
Published 2020-06-19 · Modified
7.5EPSS 0.009
CVE-2025-20630
Mobile crash via object that can't be cast to String in Attachment Field
Published 2025-01-16 · Analyzed
7.5EPSS 0.006
CVE-2025-20072
Mobile crash via improper validation of proto style in attachments
Published 2025-01-16 · Analyzed
7.5EPSS 0.005
CVE-2025-30516
Unauthorized Notification Exposure in Mobile App Under Specific Conditions
Published 2025-04-14 · Analyzed
7.5EPSS 0.003
CVE-2025-21083
Insufficient Input Validation on Post Props
Published 2025-01-15 · Analyzed
6.5EPSS 0.005
CVE-2025-20036
Insufficient Input Validation on Post Props
Published 2025-01-15 · Analyzed
6.5EPSS 0.005
CVE-2024-3872
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.
Published 2024-04-16 · Analyzed
6.5EPSS 0.005
CVE-2024-24975
Denial of Service for mobile app users due to automatic code highlighting
Published 2024-03-15 · Analyzed
6.5EPSS 0.004
CVE-2025-1558
Denial of Service Via Malicious GIF
Published 2025-03-24 · Analyzed
6.5EPSS 0.004
CVE-2024-45833
Mobile password gets saved in dictionary under conditions
Published 2024-09-16 · Analyzed
6.5EPSS 0.003
CVE-2024-39767
Spoofed push notifications from malicious server
Published 2024-07-15 · Modified
6.5EPSS 0.002
CVE-2025-59480
Inadequate validation of SSO redirect credentials permits credential theft
Published 2025-11-13 · Analyzed
6.5EPSS 0.001
CVE-2026-22880
Mobile SSO authentication flow allows credential theft via malicious server
Published 2026-05-21 · Analyzed
6.1EPSS 0.001
CVE-2024-11358
Insecure Android File Provider Paths
Published 2024-12-16 · Analyzed
5.7EPSS 0.001
CVE-2019-20850
An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2019-20849
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2024-32945
LaTeX post content manipulation via renderer state leak across contexts
Published 2024-07-15 · Modified
5.3EPSS 0.002
CVE-2025-0476
Mobile crash via file with specially crafted filename
Published 2025-01-15 · Analyzed
4.3EPSS 0.004