CVE-2026-3495
published 2026-05-18CVE-2026-3495: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition…
PriorityP422medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.14%
4.0th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-00622
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 5.3.2-0.20260310115442-5a1ea95044dc | 5.3.2-0.20260310115442-5a1ea95044dc |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20260310115442-5a1ea95044d | 8.0.0-20260310115442-5a1ea95044d |
| github.com | mattermost_mattermost_server_v8 | >= 10.11.0 < 10.11.14 | 10.11.14 |
| github.com | mattermost_mattermost_server_v8 | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 10.11.0 – 10.11.13 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost doesn't escape some variables that could contain malicious content during error page composition
ghsa·2026-05-18
CVE-2026-3495 [LOW] CWE-79 Mattermost doesn't escape some variables that could contain malicious content during error page composition
Mattermost doesn't escape some variables that could contain malicious content during error page composition
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-00622
VulDB
Mattermost up to 10.11.13/11.5.1 Configuration cross site scripting
vuldb·2026-05-18·CVSS 3.8
CVE-2026-3495 [LOW] Mattermost up to 10.11.13/11.5.1 Configuration cross site scripting
A vulnerability classified as problematic has been found in Mattermost up to 10.11.13/11.5.1. The affected element is an unknown function of the component Configuration Handler. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2026-3495. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
GHSA-jx93-pf6x-874r: Mattermost versions 11
ghsa_unreviewed·2026-05-18
CVE-2026-3495 [LOW] CWE-79 GHSA-jx93-pf6x-874r: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-00622
Citrix
Citrix Security Bulletin CTX134708
vendor_citrix·CVSS 2.1
CVE-2012-3494 [LOW] Citrix Security Bulletin CTX134708
Citrix Security Bulletin CTX134708
CVE References: CVE-2012-3494, CVE-2012-3495, CVE-2012-3496, CVE-2012-3498, CVE-2012-3516, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-18
Published