cbcvebase.

Github.Com Mattermost Mattermost-Server vulnerabilities

257 known vulnerabilities affecting github.com/mattermost_mattermost-server.

Total CVEs
257
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH26MEDIUM121LOW28UNKNOWN72

Vulnerabilities

Page 11 of 13
CVE-2024-24776P4UNKNOWN≥ 9.0.0+incompatible, < 9.3.0+incompatible2024-06-05
CVE-2024-24776 Mattermost fails to check the required permissions in github.com/mattermost/mattermost-server Mattermost fails to check the required permissions in github.com/mattermost/mattermost-server Mattermost fails to check the required permissions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerabi
osv
CVE-2025-24526P4UNKNOWN≥ 9.11.0-rc1+incompatible, < 9.11.8+incompatible≥ 10.2.0-rc1+incompatible, < 10.2.3+incompatible+2 more2025-03-03
CVE-2025-24526 Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server
osv
CVE-2025-2564P4UNKNOWN≥ 9.11.0+incompatible, < 9.11.10+incompatible≥ 10.4.0+incompatible, < 10.4.4+incompatible+1 more2025-04-22
CVE-2025-2564 Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
osv
CVE-2026-25780P4MEDIUM≥ 0, < 5.3.2-0.20260123215601-86797c508c44≥ 10.11.0-rc1, < 10.11.11+2 more2026-03-16
CVE-2026-25780 [MEDIUM] CWE-789 Mattermost fails to bound memory allocation when processing DOC files Mattermost fails to bound memory allocation when processing DOC files Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted DOC file.. Mattermost Advisory ID: MMSA-2026-00581
ghsaosv
CVE-2025-27571P4UNKNOWN≥ 9.11.0+incompatible, < 9.11.10+incompatible≥ 10.4.0+incompatible, < 10.4.4+incompatible+1 more2025-04-22
CVE-2025-27571 Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
osv
CVE-2025-3446P4UNKNOWN≥ 9.11.0+incompatible, < 9.11.12+incompatible≥ 10.4.0+incompatible, < 10.4.5+incompatible+2 more2025-05-23
CVE-2025-3446 Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server
osv
CVE-2025-1472P4MEDIUM≥ 9.11.0, < 9.11.92025-03-19
CVE-2025-1472 [MEDIUM] CWE-863 Mattermost Fails to Properly Perform Viewer Role Authorization Mattermost Fails to Properly Perform Viewer Role Authorization Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
ghsaosv
CVE-2025-3227P4MEDIUM≥ 0, < 0.0.0-20250520060012-d0380305ef7a2025-06-20
CVE-2025-3227 [MEDIUM] CWE-863 Mattermost allows unauthorized channel member management through playbook runs Mattermost allows unauthorized channel member management through playbook runs Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and pri
ghsaosv
CVE-2025-24920P4UNKNOWN≥ 9.11.0+incompatible, < 9.11.9+incompatible≥ 10.3.0+incompatible, < 10.3.4+incompatible+2 more2025-03-25
CVE-2025-24920 Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server
osv
CVE-2026-26246P4MEDIUM≥ 0, < 5.3.2-0.20260115183946-38b413a27604≥ 10.11.0-rc1, < 10.11.11+2 more2026-03-16
CVE-2026-26246 [MEDIUM] CWE-789 Mattermost fails to bound memory allocation when processing PSD image files Mattermost fails to bound memory allocation when processing PSD image files Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted PSD file. Mattermost Advisory ID: MMSA-2026-00
ghsaosv
CVE-2025-47870P4MEDIUM≥ 10.8.0, < 10.8.4≥ 10.5.0, < 10.5.9+2 more2025-08-21
CVE-2025-47870 [MEDIUM] CWE-306 Mattermost Does Not Sanitize the Team Invite ID Mattermost Does Not Sanitize the Team Invite ID Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.
ghsaosv
CVE-2026-2578P4MEDIUM≥ 0, < 5.3.2-0.20260127062706-c6b205f0d770≥ 10.11.0-rc1, < 10.11.11+2 more2026-03-16
CVE-2026-2578 [MEDIUM] CWE-201 Mattermost fails to preserve the redacted state of burn-on-read posts during deletion Mattermost fails to preserve the redacted state of burn-on-read posts during deletion Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event. Mattermost Advisory ID: MMSA-2026-00579
ghsaosv
CVE-2025-49810P4LOW≥ 10.5.0, < 10.5.92025-08-21
CVE-2025-49810 [LOW] CWE-863 Mattermost Lack of Access Control Validation Mattermost Lack of Access Control Validation Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts
ghsaosv
CVE-2026-21386P4MEDIUM≥ 0, < 5.3.2-0.20260130144323-5bb5261c72fa≥ 10.11.0-rc1, < 10.11.11+2 more2026-03-16
CVE-2026-21386 [MEDIUM] CWE-203 Mattermost fails to use consistent error responses when handling the /mute command Mattermost fails to use consistent error responses when handling the /mute command Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent
ghsaosv
CVE-2025-9078P4MEDIUM≥ 10.8.0, < 10.8.4≥ 10.5.0, < 10.5.9+3 more2025-09-15
CVE-2025-9078 [MEDIUM] CWE-328 Mattermost makes Use of Weak Hash Mattermost makes Use of Weak Hash Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to properly validate cache keys for link metadata which allows authenticated users to access unauthorized posts and poison link previews via hash collision attacks on FNV-1 hashing.
ghsaosv
CVE-2026-6339P4MEDIUM≥ 0, < 5.3.2-0.20260327001745-7a339a6438f52026-05-18
CVE-2026-6339 [MEDIUM] CWE-346 Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without recipient consent via a crafted Markdown image ta
ghsa
CVE-2017-18889P4MEDIUM≥ 0, < 4.1.2≥ 4.2.0-rc1, < 4.2.1+1 more2022-05-24
CVE-2017-18889 [MEDIUM] CWE-20 Mattermost Server is vulnerable to webhook and slash command manipulation Mattermost Server is vulnerable to webhook and slash command manipulation An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.
ghsaosv
CVE-2024-4182P4MEDIUM≥ 8.1.0, < 8.1.12≥ 9.4.0, < 9.4.5+2 more2024-04-26
CVE-2024-4182 [MEDIUM] CWE-754 Mattermost crashes web clients via a malformed custom status Mattermost crashes web clients via a malformed custom status Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
ghsaosv
CVE-2024-1952P4UNKNOWN≥ 9.0.0+incompatible, < 9.4.0+incompatible2024-06-05
CVE-2024-1952 Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server
osv
CVE-2024-1942P4UNKNOWN≥ 9.2.0+incompatible, < 9.2.5+incompatible≥ 9.3.0+incompatible, < 9.3.1+incompatible2024-06-28
CVE-2024-1942 Mattermost allows attackers access to posts in channels they are not a member of in github.com/mattermost/mattermost-server Mattermost allows attackers access to posts in channels they are not a member of in github.com/mattermost/mattermost-server Mattermost allows attackers access to posts in channels they are not a member of in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped t
osv
Github.Com Mattermost Mattermost-Server vulnerabilities | cvebase