Vulnerabilities > Mattermost > Mattermost Server > 9.2.0

DATE CVE VULNERABILITY TITLE RISK
2024-02-09 CVE-2024-1402 Resource Exhaustion vulnerability in Mattermost Server
Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post. 
network
low complexity
mattermost CWE-400
4.3
2024-01-02 CVE-2023-47858 Unspecified vulnerability in Mattermost Server
Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
network
low complexity
mattermost
4.3