cbcvebase.

Github.Com Mattermost Mattermost-Server vulnerabilities

257 known vulnerabilities affecting github.com/mattermost_mattermost-server.

Total CVEs
257
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH26MEDIUM121LOW28UNKNOWN72

Vulnerabilities

Page 8 of 13
CVE-2016-11082P4MEDIUM≥ 0, < 2.2.02022-05-24
CVE-2016-11082 [MEDIUM] CWE-79 Mattermost Server is vulnerable to XSS through crafted links Mattermost Server is vulnerable to XSS through crafted links An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
ghsaosv
CVE-2017-18904P4MEDIUM≥ 0, < 3.9.2≥ 3.10.0, < 3.10.22022-05-24
CVE-2017-18904 [MEDIUM] CWE-79 Mattermost Server vulnerable to XSS via an uploaded file Mattermost Server vulnerable to XSS via an uploaded file An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.
ghsaosv
CVE-2017-18897P4MEDIUM≥ 0, < 4.0.5≥ 4.1.0, < 4.1.1+1 more2022-05-24
CVE-2017-18897 [MEDIUM] CWE-601 Mattermost Server mishandles redirect denial action Mattermost Server mishandles redirect denial action An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
ghsaosv
CVE-2016-11083P4MEDIUM≥ 0, < 2.2.02022-05-24
CVE-2016-11083 [MEDIUM] CWE-79 Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
ghsaosv
CVE-2016-11070P4MEDIUM≥ 0, < 3.1.02022-05-24
CVE-2016-11070 [MEDIUM] CWE-79 Mattermost Server is vulnerable to XSS through customizable theme color-code values Mattermost Server is vulnerable to XSS through customizable theme color-code values An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
ghsaosv
CVE-2024-39839P4UNKNOWN≥ 9.5.0+incompatible, < 9.5.7+incompatible≥ 9.7.0+incompatible, < 9.7.6+incompatible+2 more2024-08-06
CVE-2024-39839 Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server
osv
CVE-2025-8402P4MEDIUM≥ 10.8.0, < 10.8.4≥ 10.5.0, < 10.5.9+3 more2025-08-21
CVE-2025-8402 [MEDIUM] CWE-476 Mattermost has Potential Server Crash due to Unvalidated Import Data Mattermost has Potential Server Crash due to Unvalidated Import Data Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.
ghsaosv
CVE-2026-4646P4MEDIUM≥ 11.6.0, < 11.6.1≥ 11.5.0, < 11.5.4+2 more2026-05-26
CVE-2026-4646 [MEDIUM] CWE-1287 Mattermost doesn't validate user-supplied input in API request handlers Mattermost doesn't validate user-supplied input in API request handlers Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to crash the plugin process via a crafted HTTP request to the PR details endpoint. Mattermost Advisory ID: MMSA-2026-00638
ghsa
CVE-2026-22892P4MEDIUM≥ 11.2.0, < 11.2.2≥ 11.1.0, < 11.1.3+1 more2026-02-13
CVE-2026-22892 [MEDIUM] CWE-863 Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels th
ghsaosv
CVE-2025-3611P4UNKNOWN≥ 9.0.0-rc1+incompatible, < 9.11.13+incompatible≥ 10.0.0-rc1+incompatible, < 10.5.4+incompatible+1 more2025-06-03
CVE-2025-3611 Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server
osv
CVE-2025-11776P4MEDIUM≥ 0, < 5.3.2-0.20250815165020-c8d66301415d2025-11-14
CVE-2025-11776 [MEDIUM] CWE-863 Mattermost fails to properly restrict access to archived channel search API Mattermost fails to properly restrict access to archived channel search API Mattermost versions < 11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint
ghsaosv
CVE-2024-41926P4UNKNOWN≥ 9.5.0+incompatible, < 9.5.7+incompatible≥ 9.9.0+incompatible, < 9.9.1+incompatible2024-08-06
CVE-2024-41926 Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server
osv
CVE-2026-6689P4MEDIUM≥ 11.6.0, < 11.6.1≥ 11.5.0, < 11.5.5+1 more2026-06-12
CVE-2026-6689 [MEDIUM] CWE-862 Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation (the check was only applied on upd
ghsa
CVE-2026-28759P4MEDIUM≥ 0, < 5.3.2-0.20260216150504-8738f8c4b3d42026-05-18
CVE-2026-28759 [MEDIUM] CWE-863 Mattermost does not verify remote cluster channel access when processing shared channel membership removals Mattermost does not verify remote cluster channel access when processing shared channel membership removals Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious re
ghsa
CVE-2026-28732P4MEDIUM≥ 0, < 5.3.2-0.20260306123948-f5fe8ded6b632026-05-18
CVE-2026-28732 [MEDIUM] CWE-863 Mattermost doesn't enforce slash command trigger-word uniqueness during command updates Mattermost doesn't enforce slash command trigger-word uniqueness during command updates Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom sl
ghsa
CVE-2026-2457P4MEDIUM≥ 0, < 5.3.2-0.20260123211116-9efe617be8b8≥ 10.11.0-rc1, < 10.11.11+2 more2026-03-16
CVE-2026-2457 [MEDIUM] CWE-346 Mattermost allows attackers to spoof permalink embeds Mattermost allows attackers to spoof permalink embeds Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint. Mattermost Advisory ID: MMSA-2025-00569
ghsaosv
CVE-2017-18887P4MEDIUM≥ 0, < 4.1.2≥ 4.2.0-rc1, < 4.2.1+1 more2022-05-24
CVE-2017-18887 [MEDIUM] CWE-200 Mattermost Server exposes team creator's e-mail address to other members Mattermost Server exposes team creator's e-mail address to other members An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
ghsaosv
CVE-2016-11075P4MEDIUM≥ 0, < 2.0.1-0.20160310160916-26ad6d2c76962022-05-24
CVE-2016-11075 [MEDIUM] CWE-200 Mattermost Server exposes sensitive information about team URLs via an API Mattermost Server exposes sensitive information about team URLs via an API An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
ghsaosv
CVE-2016-11071P4MEDIUM≥ 0, < 3.1.02022-05-24
CVE-2016-11071 [MEDIUM] CWE-79 Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener` Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener` An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
ghsaosv
CVE-2016-11073P4MEDIUM≥ 0, < 3.0.02022-05-24
CVE-2016-11073 [MEDIUM] CWE-79 Mattermost Server is vulnerable to XSS via a Legal or Support setting Mattermost Server is vulnerable to XSS via a Legal or Support setting An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
ghsaosv
Github.Com Mattermost Mattermost-Server vulnerabilities | cvebase