Github.Com Mattermost Mattermost-Server vulnerabilities
257 known vulnerabilities affecting github.com/mattermost_mattermost-server.
Total CVEs
257
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH26MEDIUM121LOW28UNKNOWN72
Vulnerabilities
Page 8 of 13
CVE-2016-11082P4MEDIUM≥ 0, < 2.2.02022-05-24
CVE-2016-11082 [MEDIUM] CWE-79 Mattermost Server is vulnerable to XSS through crafted links
Mattermost Server is vulnerable to XSS through crafted links
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
ghsaosv
CVE-2017-18904P4MEDIUM≥ 0, < 3.9.2≥ 3.10.0, < 3.10.22022-05-24
CVE-2017-18904 [MEDIUM] CWE-79 Mattermost Server vulnerable to XSS via an uploaded file
Mattermost Server vulnerable to XSS via an uploaded file
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.
ghsaosv
CVE-2017-18897P4MEDIUM≥ 0, < 4.0.5≥ 4.1.0, < 4.1.1+1 more2022-05-24
CVE-2017-18897 [MEDIUM] CWE-601 Mattermost Server mishandles redirect denial action
Mattermost Server mishandles redirect denial action
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
ghsaosv
CVE-2016-11083P4MEDIUM≥ 0, < 2.2.02022-05-24
CVE-2016-11083 [MEDIUM] CWE-79 Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
ghsaosv
CVE-2016-11070P4MEDIUM≥ 0, < 3.1.02022-05-24
CVE-2016-11070 [MEDIUM] CWE-79 Mattermost Server is vulnerable to XSS through customizable theme color-code values
Mattermost Server is vulnerable to XSS through customizable theme color-code values
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
ghsaosv
CVE-2024-39839P4UNKNOWN≥ 9.5.0+incompatible, < 9.5.7+incompatible≥ 9.7.0+incompatible, < 9.7.6+incompatible+2 more2024-08-06
CVE-2024-39839 Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server
Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server
Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server
osv
CVE-2025-8402P4MEDIUM≥ 10.8.0, < 10.8.4≥ 10.5.0, < 10.5.9+3 more2025-08-21
CVE-2025-8402 [MEDIUM] CWE-476 Mattermost has Potential Server Crash due to Unvalidated Import Data
Mattermost has Potential Server Crash due to Unvalidated Import Data
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.
ghsaosv
CVE-2026-4646P4MEDIUM≥ 11.6.0, < 11.6.1≥ 11.5.0, < 11.5.4+2 more2026-05-26
CVE-2026-4646 [MEDIUM] CWE-1287 Mattermost doesn't validate user-supplied input in API request handlers
Mattermost doesn't validate user-supplied input in API request handlers
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to crash the plugin process via a crafted HTTP request to the PR details endpoint. Mattermost Advisory ID: MMSA-2026-00638
ghsa
CVE-2026-22892P4MEDIUM≥ 11.2.0, < 11.2.2≥ 11.1.0, < 11.1.3+1 more2026-02-13
CVE-2026-22892 [MEDIUM] CWE-863 Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts
Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels th
ghsaosv
CVE-2025-3611P4UNKNOWN≥ 9.0.0-rc1+incompatible, < 9.11.13+incompatible≥ 10.0.0-rc1+incompatible, < 10.5.4+incompatible+1 more2025-06-03
CVE-2025-3611 Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server
osv
CVE-2025-11776P4MEDIUM≥ 0, < 5.3.2-0.20250815165020-c8d66301415d2025-11-14
CVE-2025-11776 [MEDIUM] CWE-863 Mattermost fails to properly restrict access to archived channel search API
Mattermost fails to properly restrict access to archived channel search API
Mattermost versions < 11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint
ghsaosv
CVE-2024-41926P4UNKNOWN≥ 9.5.0+incompatible, < 9.5.7+incompatible≥ 9.9.0+incompatible, < 9.9.1+incompatible2024-08-06
CVE-2024-41926 Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server
Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server
Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server
osv
CVE-2026-6689P4MEDIUM≥ 11.6.0, < 11.6.1≥ 11.5.0, < 11.5.5+1 more2026-06-12
CVE-2026-6689 [MEDIUM] CWE-862 Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation (the check was only applied on upd
ghsa
CVE-2026-28759P4MEDIUM≥ 0, < 5.3.2-0.20260216150504-8738f8c4b3d42026-05-18
CVE-2026-28759 [MEDIUM] CWE-863 Mattermost does not verify remote cluster channel access when processing shared channel membership removals
Mattermost does not verify remote cluster channel access when processing shared channel membership removals
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious re
ghsa
CVE-2026-28732P4MEDIUM≥ 0, < 5.3.2-0.20260306123948-f5fe8ded6b632026-05-18
CVE-2026-28732 [MEDIUM] CWE-863 Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom sl
ghsa
CVE-2026-2457P4MEDIUM≥ 0, < 5.3.2-0.20260123211116-9efe617be8b8≥ 10.11.0-rc1, < 10.11.11+2 more2026-03-16
CVE-2026-2457 [MEDIUM] CWE-346 Mattermost allows attackers to spoof permalink embeds
Mattermost allows attackers to spoof permalink embeds
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint. Mattermost Advisory ID: MMSA-2025-00569
ghsaosv
CVE-2017-18887P4MEDIUM≥ 0, < 4.1.2≥ 4.2.0-rc1, < 4.2.1+1 more2022-05-24
CVE-2017-18887 [MEDIUM] CWE-200 Mattermost Server exposes team creator's e-mail address to other members
Mattermost Server exposes team creator's e-mail address to other members
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
ghsaosv
CVE-2016-11075P4MEDIUM≥ 0, < 2.0.1-0.20160310160916-26ad6d2c76962022-05-24
CVE-2016-11075 [MEDIUM] CWE-200 Mattermost Server exposes sensitive information about team URLs via an API
Mattermost Server exposes sensitive information about team URLs via an API
An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
ghsaosv
CVE-2016-11071P4MEDIUM≥ 0, < 3.1.02022-05-24
CVE-2016-11071 [MEDIUM] CWE-79 Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
ghsaosv
CVE-2016-11073P4MEDIUM≥ 0, < 3.0.02022-05-24
CVE-2016-11073 [MEDIUM] CWE-79 Mattermost Server is vulnerable to XSS via a Legal or Support setting
Mattermost Server is vulnerable to XSS via a Legal or Support setting
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
ghsaosv