cbcvebase.

Github.Com Mattermost Mattermost Server V8 vulnerabilities

206 known vulnerabilities affecting github.com/mattermost_mattermost_server_v8.

Total CVEs
206
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM134LOW48

Vulnerabilities

Page 6 of 11
CVE-2024-39839P4MEDIUM≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-39839 [MEDIUM] CWE-284 Mattermost allows a user on a remote to set their remote username prop to an arbitrary string Mattermost allows a user on a remote to set their remote username prop to an arbitrary string Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be
ghsaosv
CVE-2025-8402P4MEDIUM≥ 0, < 8.0.0-20250708173752-d6b35c41f0ae52025-08-21
CVE-2025-8402 [MEDIUM] CWE-476 Mattermost has Potential Server Crash due to Unvalidated Import Data Mattermost has Potential Server Crash due to Unvalidated Import Data Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.
ghsaosv
CVE-2024-50052P4MEDIUM≥ 0, < 8.0.0-20240926115259-20ed58906adc2024-10-29
CVE-2024-50052 [MEDIUM] CWE-862 Mattermost server allows authenticated user to delete arbitrary post Mattermost server allows authenticated user to delete arbitrary post Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
ghsaosv
CVE-2025-3611P4LOW≥ 10.6.0-rc1, < 10.7.1≥ 10.0.0-rc1, < 10.5.4+2 more2025-05-30
CVE-2025-3611 [LOW] CWE-863 Mattermost fails to properly enforce access control restrictions for System Manager roles Mattermost fails to properly enforce access control restrictions for System Manager roles Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests t
ghsaosv
CVE-2025-13870P4LOW≥ 0, < 8.0.0-20250905150616-ba86dfc5876b2025-12-02
CVE-2025-13870 [LOW] CWE-284 Mattermost fails to validate user permissions in Boards Mattermost fails to validate user permissions in Boards Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
ghsaosv
CVE-2025-11776P4MEDIUM≥ 0, < 8.0.0-20250815165020-c8d66301415d2025-11-14
CVE-2025-11776 [MEDIUM] CWE-863 Mattermost fails to properly restrict access to archived channel search API Mattermost fails to properly restrict access to archived channel search API Mattermost versions < 11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint
ghsaosv
CVE-2024-41926P4MEDIUM≥ 9.5.0, < 9.5.7≥ 9.9.0, < 9.9.1+1 more2024-08-01
CVE-2024-41926 [MEDIUM] CWE-284 Mattermost allows remote actor to set arbitrary RemoteId values for synced users Mattermost allows remote actor to set arbitrary RemoteId values for synced users Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.
ghsaosv
CVE-2026-6689P4MEDIUM≥ 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260501144115-7d6816abdfd12026-06-12
CVE-2026-6689 [MEDIUM] CWE-862 Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation (the check was only applied on upd
ghsa
CVE-2026-28759P4MEDIUM≥ 11.5.0, < 11.5.2≥ 10.11.0, < 10.11.14+2 more2026-05-18
CVE-2026-28759 [MEDIUM] CWE-863 Mattermost does not verify remote cluster channel access when processing shared channel membership removals Mattermost does not verify remote cluster channel access when processing shared channel membership removals Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious re
ghsa
CVE-2026-28732P4MEDIUM≥ 11.5.0, < 11.5.2≥ 10.11.0, < 10.11.14+2 more2026-05-18
CVE-2026-28732 [MEDIUM] CWE-863 Mattermost doesn't enforce slash command trigger-word uniqueness during command updates Mattermost doesn't enforce slash command trigger-word uniqueness during command updates Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom sl
ghsa
CVE-2026-2457P4MEDIUM≥ 0, < 8.0.0-20260123211116-9efe617be8b82026-03-16
CVE-2026-2457 [MEDIUM] CWE-346 Mattermost allows attackers to spoof permalink embeds Mattermost allows attackers to spoof permalink embeds Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint. Mattermost Advisory ID: MMSA-2025-00569
ghsaosv
CVE-2023-5968P4MEDIUM≥ 8.0.0, < 8.0.4≥ 8.1.0, < 8.1.3+2 more2023-11-06
CVE-2023-5968 [MEDIUM] CWE-116 Mattermost password hash disclosure vulnerability Mattermost password hash disclosure vulnerability Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
ghsaosv
CVE-2024-54682P4MEDIUM≥ 10.1.0, < 10.1.3≥ 10.0.0, < 10.0.3+2 more2024-12-16
CVE-2024-54682 [MEDIUM] CWE-409 Mattermost Data Amplification vulnerability Mattermost Data Amplification vulnerability Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.
ghsaosv
CVE-2024-41162P4MEDIUM≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+3 more2024-08-01
CVE-2024-41162 [MEDIUM] CWE-284 Mattermost allows a remote actor to make an arbitrary local channel read-only Mattermost allows a remote actor to make an arbitrary local channel read-only Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.
ghsaosv
CVE-2025-41423P4LOW≥ 0, < 8.0.0-20250218121836-2b5275d87136≥ 10.4.0+2 more2025-04-24
CVE-2025-41423 [LOW] CWE-863 Mattermost Playbooks fails to properly validate permissions Mattermost Playbooks fails to properly validate permissions Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.
ghsaosv
CVE-2024-48872P4MEDIUM≥ 10.1.0, < 10.1.3≥ 10.0.0, < 10.0.3+2 more2024-12-16
CVE-2024-48872 [MEDIUM] CWE-362 Mattermost Race Condition vulnerability Mattermost Race Condition vulnerability Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests
ghsaosv
CVE-2025-12559P4MEDIUM≥ 0, < 8.0.0-20251015091448-abbf01b9db452025-11-27
CVE-2025-12559 [MEDIUM] CWE-200 Mattermost fails to sanitize team email addresses Mattermost fails to sanitize team email addresses Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
ghsaosv
CVE-2025-13767P4MEDIUM≥ 0, < 8.0.0-20251121122154-b57c297c6d72025-12-24
CVE-2025-13767 [MEDIUM] CWE-863 Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with acce
ghsaosv
CVE-2026-3433P4MEDIUM≥ 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260504071740-9408b98025d72026-06-12
CVE-2026-3433 [MEDIUM] CWE-200 Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_updated websocket event broadcasts to members of the affected team or channel, which allows an authenticated attacker with gues
ghsa
CVE-2026-0999P4MEDIUM≥ 0, < 8.0.0-20251212052346-61651b0df7ea2026-02-16
CVE-2026-0999 [MEDIUM] CWE-303 Mattermost fails to properly validate login method restrictions Mattermost fails to properly validate login method restrictions Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548
ghsaosv
Github.Com Mattermost Mattermost Server V8 vulnerabilities | cvebase