cbcvebase.

Github.Com Mattermost Mattermost-Server vulnerabilities

257 known vulnerabilities affecting github.com/mattermost_mattermost-server.

Total CVEs
257
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH26MEDIUM121LOW28UNKNOWN72

Vulnerabilities

Page 10 of 13
CVE-2024-32046P4MEDIUM≥ 8.1.0, < 8.1.12≥ 9.5.0, < 9.5.3+2 more2024-04-26
CVE-2024-32046 [MEDIUM] CWE-200 Mattermost's detailed error messages reveal the full file path Mattermost's detailed error messages reveal the full file path Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
ghsaosv
CVE-2016-11084P4MEDIUM≥ 0, < 2.1.02022-05-24
CVE-2016-11084 [MEDIUM] CWE-352 Mattermost Server allows XSS via CSRF Mattermost Server allows XSS via CSRF An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
ghsaosv
CVE-2024-23488P4UNKNOWN≥ 9.0.0+incompatible, < 9.4.2+incompatible2024-06-28
CVE-2024-23488 Mattermost fails to properly restrict the access of files attached to posts in github.com/mattermost/mattermost-server Mattermost fails to properly restrict the access of files attached to posts in github.com/mattermost/mattermost-server Mattermost fails to properly restrict the access of files attached to posts in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go
osv
CVE-2025-10545P4LOW≥ 10.5.0, < 10.5.11≥ 10.11.0, < 10.11.32025-10-16
CVE-2025-10545 [LOW] CWE-863 Mattermost has an Incorrect Authorization vulnerability Mattermost has an Incorrect Authorization vulnerability Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint
ghsaosv
CVE-2025-2527P4UNKNOWN≥ 9.11.0+incompatible, < 9.11.12+incompatible≥ 10.5.0+incompatible, < 10.5.3+incompatible2025-05-23
CVE-2025-2527 Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server
osv
CVE-2026-25783P4MEDIUM≥ 0, < 5.3.2-0.20260129181235-1346cf529aef≥ 10.11.0-rc1, < 10.11.11+2 more2026-03-16
CVE-2026-25783 [MEDIUM] CWE-1287 Mattermost fails to properly validate User-Agent header tokens Mattermost fails to properly validate User-Agent header tokens Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586
ghsaosv
CVE-2025-41443P4MEDIUM≥ 10.5.0, < 10.5.11≥ 10.11.0, < 10.11.32025-10-16
CVE-2025-41443 [MEDIUM] CWE-862 Mattermost has a Missing Authorization vulnerability Mattermost has a Missing Authorization vulnerability Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_id}/channels/ids` endpoint
ghsaosv
CVE-2024-43780P4UNKNOWN≥ 9.5.0+incompatible, < 9.5.8+incompatible≥ 9.8.0+incompatible, < 9.8.3+incompatible+2 more2024-08-30
CVE-2024-43780 Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server
osv
CVE-2025-3228P4MEDIUM≥ 0, < 0.0.0-20250520060012-d0380305ef7a2025-06-20
CVE-2025-3228 [MEDIUM] CWE-863 Mattermost allows an unauthorized Guest user access to Playbook Mattermost allows an unauthorized Guest user access to Playbook Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run.
ghsaosv
CVE-2025-2424P4UNKNOWN≥ 9.11.0+incompatible, < 9.11.10+incompatible≥ 10.5.0+incompatible, < 10.5.2+incompatible2025-04-22
CVE-2025-2424 Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
osv
CVE-2025-24839P4UNKNOWN≥ 9.11.0+incompatible, < 9.11.10+incompatible≥ 10.4.0+incompatible, < 10.4.4+incompatible+1 more2025-04-22
CVE-2025-24839 Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
osv
CVE-2025-4128P4LOW≥ 10.5.0, < 10.5.5≥ 9.11.0, < 9.11.142025-06-11
CVE-2025-4128 [LOW] CWE-863 Mattermost allows guest users to view information about public teams they are not members of Mattermost allows guest users to view information about public teams they are not members of Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
ghsaosv
CVE-2025-2571P4UNKNOWN≥ 9.0.0-rc1+incompatible, < 9.11.13+incompatible≥ 10.0.0-rc1+incompatible, < 10.5.4+incompatible+2 more2025-06-03
CVE-2025-2571 Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server
osv
CVE-2025-11777P4LOW≥ 10.11.0, < 10.11.4≥ 10.5.0, < 10.5.12+1 more2025-11-13
CVE-2025-11777 [LOW] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API, which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint.
ghsaosv
CVE-2025-41436P4LOW≥ 0, < 11.0.0-alpha.12025-11-14
CVE-2025-41436 [LOW] CWE-863 Mattermost allows regular users to access archived channel content and files Mattermost allows regular users to access archived channel content and files Mattermost versions < 11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads
ghsaosv
CVE-2025-14350P4MEDIUM≥ 11.1.0≥ 10.11.0+2 more2026-02-16
CVE-2025-14350 [MEDIUM] CWE-862 Mattermost fails to properly validate team membership when processing channel mentions Mattermost fails to properly validate team membership when processing channel mentions Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and observing the chann
ghsaosv
CVE-2026-3495P4LOW≥ 0, < 5.3.2-0.20260310115442-5a1ea95044dc2026-05-18
CVE-2026-3495 [LOW] CWE-79 Mattermost doesn't escape some variables that could contain malicious content during error page composition Mattermost doesn't escape some variables that could contain malicious content during error page composition Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code v
ghsa
CVE-2017-18873P4MEDIUM≥ 0, < 4.1.2-0.20171013141717-ee57a5829ab1≥ 4.2.0, < 4.2.1-0.20171013140502-b3e4b0ac9168+1 more2022-05-24
CVE-2017-18873 [MEDIUM] CWE-20 Mattermost Server is vulnerable to channel invisibility DoS via misformatted post Mattermost Server is vulnerable to channel invisibility DoS via misformatted post An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformated post.
ghsaosv
CVE-2024-1953P4UNKNOWN≥ 9.2.0+incompatible, < 9.2.5+incompatible≥ 9.3.0+incompatible, < 9.3.1+incompatible+1 more2024-06-28
CVE-2024-1953 Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerabil
osv
CVE-2024-1887P4UNKNOWN≥ 9.2.0+incompatible, < 9.2.5+incompatible≥ 9.3.0+incompatible, < 9.3.1+incompatible2024-06-28
CVE-2024-1887 Mattermost post fetching without auditing in compliance export in github.com/mattermost/mattermost-server Mattermost post fetching without auditing in compliance export in github.com/mattermost/mattermost-server Mattermost post fetching without auditing in compliance export in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing fa
osv
Github.Com Mattermost Mattermost-Server vulnerabilities | cvebase