Mattermost Mobile
Vendor:
First CVE: Jun 19, 2020 · Active for 6 years
20
Total CVEs
More Total CVEs than 95% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mattermost Mobile over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2020
6 years ago
Most Recent CVE
Nov 13, 2025
257 days ago
CVE Severity & Scoring
Mattermost Mobile20 CVEs
65%
35%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (90.0%)
Unknown0 (0.0%)
Required2 (10.0%)
Privileges Required
Low7 (35.0%)
High0 (0.0%)
None13 (65.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14451HIGH An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013. | Jun 19, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-20848HIGH An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies. | Jun 19, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-20852HIGH An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content). | Jun 19, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-14449HIGH An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018. | Jun 19, 2020 | 7.5 | 23 | NO | NO |
CVE-2025-20630HIGH Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile t | Jan 16, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-59480MEDIUM Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker | Nov 13, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-20072HIGH Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mob | Jan 16, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-30516HIGH Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices | Apr 14, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-39767MEDIUM Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to se | Jul 15, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-3872MEDIUM Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to | Apr 16, 2024 | 6.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Mattermost Mobile
Top CWEs
Versions
No cataloged versions.