cbcvebase.

Github.Com Mattermost Mattermost Server V8 vulnerabilities

206 known vulnerabilities affecting github.com/mattermost_mattermost_server_v8.

Total CVEs
206
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM134LOW48

Vulnerabilities

Page 11 of 11
CVE-2024-1949P4LOW≥ 9.0.0, < 9.4.2≥ 0, < 8.1.92024-02-29
CVE-2024-1949 [LOW] CWE-200 Mattermost race condition Mattermost race condition A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.
ghsaosv
CVE-2025-27538P4LOW≥ 10.5.0, < 10.5.2≥ 9.11.0, < 9.11.10+1 more2025-04-16
CVE-2025-27538 [LOW] CWE-306 Mattermost Missing Authentication for Critical Function Mattermost Missing Authentication for Critical Function Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if those users have not set up MFA.
ghsaosv
CVE-2023-5193P4LOW≥ 8.1.0, < 8.1.1≥ 8.0.0, < 8.0.22023-09-29
CVE-2023-5193 [LOW] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.
ghsaosv
CVE-2024-40884P4MEDIUM≥ 9.5.0, < 9.5.8≥ 9.10.0, < 9.10.12024-08-22
CVE-2024-40884 [MEDIUM] CWE-284 Mattermost allows team admin user without "Add Team Members" permission to disable invite URL Mattermost allows team admin user without "Add Team Members" permission to disable invite URL Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
ghsaosv
CVE-2023-5159P4LOW≥ 8.1.0, < 8.1.1≥ 8.0.0, < 8.0.22023-09-29
CVE-2023-5159 [LOW] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.
ghsaosv
CVE-2025-27715P4LOW≥ 9.11.0, < 9.11.92025-03-21
CVE-2025-27715 [LOW] CWE-863 Mattermost fail to prompt for explicit approval before adding a team admin to a private channel Mattermost fail to prompt for explicit approval before adding a team admin to a private channel Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.
ghsaosv
Github.Com Mattermost Mattermost Server V8 vulnerabilities | cvebase