cbcvebase.

Github.Com Mattermost Mattermost Server V8 vulnerabilities

206 known vulnerabilities affecting github.com/mattermost_mattermost_server_v8.

Total CVEs
206
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM134LOW48

Vulnerabilities

Page 4 of 11
CVE-2025-41410P3MEDIUM≥ 0, < 8.0.0-20250822083415-01b95392a4502025-10-16
CVE-2025-41410 [MEDIUM] CWE-862 Mattermost has a Missing Authorization vulnerability Mattermost has a Missing Authorization vulnerability Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verified user accounts with arbitrary email domains via malicious Slack import data to bypass email-based team access restrictions.
ghsaosv
CVE-2026-27656P4MEDIUM≥ 8.0.0-20260105080200-d27a2195068d, < 8.0.0-20260217110922-b7d4a1f1f59b2026-03-25
CVE-2026-27656 [MEDIUM] CWE-303 Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts
ghsaosv
CVE-2024-28949P4MEDIUM≥ 8.1.0, < 8.1.11≥ 9.3.0, < 9.3.3+2 more2024-04-05
CVE-2024-28949 [MEDIUM] CWE-400 Mattermost Server doesn't limit the number of user preferences Mattermost Server doesn't limit the number of user preferences Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
ghsaosv
CVE-2025-27936P4MEDIUM≥ 10.5.0, < 10.5.2≥ 0, < 8.0.0-20250314142426-c049748b88632025-04-16
CVE-2025-27936 [MEDIUM] CWE-208 Mattermost vulnerable to Observable Timing Discrepancy Mattermost vulnerable to Observable Timing Discrepancy Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.
ghsaosv
CVE-2024-36492P4MEDIUM≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-36492 [MEDIUM] CWE-284 Mattermost failed to disallow the modification of local users when syncing users in shared channels Mattermost failed to disallow the modification of local users when syncing users in shared channels Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.
ghsaosv
CVE-2024-39837P4LOW≥ 9.5.0, < 9.5.7≥ 9.9.0, < 9.9.1+1 more2024-08-01
CVE-2024-39837 [LOW] CWE-284 Mattermost did not properly restrict channel creation Mattermost did not properly restrict channel creation Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.
ghsaosv
CVE-2026-3112P4MEDIUM≥ 11.4.0-rc1, < 11.4.1≥ 11.3.0-rc1, < 11.3.2+3 more2026-03-26
CVE-2026-3112 [MEDIUM] CWE-22 Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced Logging file target paths which allows system administrators to read arbitrary host files via malicious AdvancedLog
ghsaosv
CVE-2026-6046P4MEDIUM≥ 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260428151657-c79c3831061a2026-06-12
CVE-2026-6046 [MEDIUM] CWE-200 Mattermost doesn't validate that a username returned during bot registration belongs to a bot account Mattermost doesn't validate that a username returned during bot registration belongs to a bot account Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged attacker to intercept private messages sent by
ghsa
CVE-2025-6233P4MEDIUM≥ 0, < 8.0.0-20250529054450-d38c27f96fcf2025-07-18
CVE-2025-6233 [MEDIUM] CWE-22 Mattermost Path Traversal vulnerability Mattermost Path Traversal vulnerability Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.
ghsaosv
CVE-2025-3230P4MEDIUM≥ 10.7.0-rc1, < 10.7.1≥ 10.6.0-rc1, < 10.6.3+3 more2025-05-30
CVE-2025-3230 [MEDIUM] CWE-303 Mattermost fails to properly invalidate personal access tokens upon user deactivation Mattermost fails to properly invalidate personal access tokens upon user deactivation Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of pre
ghsaosv
CVE-2025-13821P4MEDIUM≥ 0, < 8.0.0-20251210191531-cd17b61de41b2026-02-16
CVE-2025-13821 [MEDIUM] CWE-200 Mattermost fails to sanitize sensitive data in WebSocket messages Mattermost fails to sanitize sensitive data in WebSocket messages Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost Advisory ID: MMSA-2025-00560
ghsaosv
CVE-2025-55073P4MEDIUM≥ 0, < 8.0.0-20250929212932-a41db04d27462025-11-14
CVE-2025-55073 [MEDIUM] CWE-306 Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth re
ghsaosv
CVE-2025-46702P4MEDIUM≥ 0, < 8.0.0-20250513065225-4ae5d647fb88≥ 9.11.0, < 9.11.16+4 more2025-06-30
CVE-2025-46702 [MEDIUM] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from private channels via th
ghsaosv
CVE-2026-4274P4MEDIUM≥ 11.4.0-rc1, < 11.4.1≥ 11.3.0-rc1, < 11.3.2+3 more2026-03-26
CVE-2026-4274 [MEDIUM] CWE-863 Mattermost has an Incorrect Authorization issue Mattermost has an Incorrect Authorization issue Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user access to an entire private team instead of only the shared channel via sending crafted membership sync messages that trigger team m
ghsaosv
CVE-2023-5969P4MEDIUM≥ 8.0.0, < 8.0.4≥ 8.1.0, < 8.1.3+1 more2023-11-06
CVE-2023-5969 [MEDIUM] CWE-400 Mattermost vulnerable to excessive memory consumption Mattermost vulnerable to excessive memory consumption Mattermost fails to properly sanitize the request to `/api/v4/redirect_location` allowing an attacker, sending a specially crafted request to `/api/v4/redirect_location`, to fill up the memory due to caching large items.
ghsaosv
CVE-2025-2475P4MEDIUM≥ 10.5.0, < 10.5.2≥ 9.11.0, < 9.11.10+1 more2025-04-14
CVE-2025-2475 [MEDIUM] CWE-303 Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
ghsaosv
CVE-2025-47871P4MEDIUM≥ 0, < 8.0.0-20250513065225-4ae5d647fb88≥ 9.11.0, < 9.11.16+4 more2025-06-30
CVE-2025-47871 [MEDIUM] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel name, display nam
ghsaosv
CVE-2023-7113P4LOW≥ 0, < 8.1.72023-12-29
CVE-2023-7113 [LOW] CWE-79 Mattermost Cross-site Scripting vulnerability Mattermost Cross-site Scripting vulnerability Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
ghsaosv
CVE-2025-11794P4MEDIUM≥ 0, < 8.0.0-20250929212932-a41db04d27462025-11-14
CVE-2025-11794 [MEDIUM] CWE-200 Mattermost allows system administrators to access password hashes and MFA secrets Mattermost allows system administrators to access password hashes and MFA secrets Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and MFA secrets via the POST /api/v4/users/{user_id}/email/verify/member endpoint
ghsaosv
CVE-2026-2456P4MEDIUM≥ 0, < 8.0.0-20260127165411-fe3052073dc62026-03-16
CVE-2026-2456 [MEDIUM] CWE-789 Mattermost fails to limit the size of responses from integration action endpoints Mattermost fails to limit the size of responses from integration action endpoints Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker to cause server memory exhaustion and denial of service via a malicious integration server that returns an
ghsaosv
Github.Com Mattermost Mattermost Server V8 vulnerabilities | cvebase