← All credits
Doyensec
33 vulnerability records and advisories credit this contributor.
CVE-2026-59335
Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA Compromise
CVE-2026-22880
Mobile SSO authentication flow allows credential theft via malicious server
CVE-2025-9072
One-Click Mattermost Account Takeover via Poisoned RelayState SAML Parameter
CVE-2025-62190
CSRF Allows Call Initiation and Message Delivery
CVE-2025-59480
Inadequate validation of SSO redirect credentials permits credential theft
CVE-2025-58084
Mattermost Desktop App crashes when clicking on malformed external URL
CVE-2025-58075
Arbitrary Mattermost Team can be joined by manipulating the SAML RelayState
CVE-2025-58073
Arbitrary Mattermost Team can be joined by manipulating the OAuth state
CVE-2025-55035
Mattermost Desktop DoS when user has basic authentication server configured
CVE-2025-54499
Insecure string comparison enables timing attacks