Total vulnerabilities in the database
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
CVSS v3:
CWEs:
OWASP TOP 10: