Github.Com Mattermost Mattermost Server V8 vulnerabilities
206 known vulnerabilities affecting github.com/mattermost_mattermost_server_v8.
Total CVEs
206
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM134LOW48
Vulnerabilities
Page 9 of 11
CVE-2026-26246P4MEDIUM≥ 0, < 8.0.0-20260115183946-38b413a276042026-03-16
CVE-2026-26246 [MEDIUM] CWE-789 Mattermost fails to bound memory allocation when processing PSD image files
Mattermost fails to bound memory allocation when processing PSD image files
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted PSD file. Mattermost Advisory ID: MMSA-2026-00
ghsaosv
CVE-2025-47870P4MEDIUM≥ 0, < 8.0.0-20250708065844-b38e2eccda182025-08-21
CVE-2025-47870 [MEDIUM] CWE-306 Mattermost Does Not Sanitize the Team Invite ID
Mattermost Does Not Sanitize the Team Invite ID
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.
ghsaosv
CVE-2026-2578P4MEDIUM≥ 0, < 8.0.0-20260127062706-c6b205f0d7702026-03-16
CVE-2026-2578 [MEDIUM] CWE-201 Mattermost fails to preserve the redacted state of burn-on-read posts during deletion
Mattermost fails to preserve the redacted state of burn-on-read posts during deletion
Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event. Mattermost Advisory ID: MMSA-2026-00579
ghsaosv
CVE-2025-49810P4LOW≥ 0, < 8.0.0-20250721095846-c602a4a78e1f2025-08-21
CVE-2025-49810 [LOW] CWE-863 Mattermost Lack of Access Control Validation
Mattermost Lack of Access Control Validation
Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts
ghsaosv
CVE-2026-21386P4MEDIUM≥ 0, < 8.0.0-20260130144323-5bb5261c72fa2026-03-16
CVE-2026-21386 [MEDIUM] CWE-203 Mattermost fails to use consistent error responses when handling the /mute command
Mattermost fails to use consistent error responses when handling the /mute command
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent
ghsaosv
CVE-2025-9078P4MEDIUM≥ 0, < 8.0.0-20250718075842-cd87e5c877372025-09-15
CVE-2025-9078 [MEDIUM] CWE-328 Mattermost makes Use of Weak Hash
Mattermost makes Use of Weak Hash
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to properly validate cache keys for link metadata which allows authenticated users to access unauthorized posts and poison link previews via hash collision attacks on FNV-1 hashing.
ghsaosv
CVE-2026-6339P4MEDIUM≥ 11.5.0, < 11.5.2≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-6339 [MEDIUM] CWE-346 Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without recipient consent via a crafted Markdown image ta
ghsa
CVE-2023-5967P4MEDIUM≥ 8.0.0, < 8.0.4≥ 8.1.0, < 8.1.3+1 more2023-11-06
CVE-2023-5967 [MEDIUM] CWE-754 Mattermost denial of service vulnerability
Mattermost denial of service vulnerability
Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin
ghsaosv
CVE-2023-45223P4MEDIUM≥ 0, < 8.1.42023-11-27
CVE-2023-45223 [MEDIUM] CWE-200 Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled.
ghsaosv
CVE-2023-43754P4MEDIUM≥ 9.1.0, < 9.1.1≥ 9.0.0, < 9.0.2+1 more2023-11-27
CVE-2023-43754 [MEDIUM] CWE-200 Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost fails to check whether the "Allow users to view archived channels" setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the "Allow users to view archived channels" setting is disabled.
ghsaosv
CVE-2024-1952P4LOW≥ 9.0.0, < 9.4.02024-02-29
CVE-2024-1952 [LOW] CWE-200 Mattermost incorrectly allows access individual posts
Mattermost incorrectly allows access individual posts
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.
ghsaosv
CVE-2024-1942P4MEDIUM≥ 9.3.0, < 9.3.1≥ 9.2.0, < 9.2.5+1 more2024-02-29
CVE-2024-1942 [MEDIUM] CWE-284 Mattermost allows attackers access to posts in channels they are not a member of
Mattermost allows attackers access to posts in channels they are not a member of
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.
ghsaosv
CVE-2023-47858P4MEDIUM≥ 0, < 8.1.12024-01-02
CVE-2023-47858 [MEDIUM] CWE-284 Mattermost viewing archived public channels permissions vulnerability
Mattermost viewing archived public channels permissions vulnerability
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams//channels/deleted endpoint.
ghsaosv
CVE-2025-27933P4MEDIUM≥ 10.4.0, < 10.4.3≥ 10.3.0, < 10.3.4+2 more2025-03-21
CVE-2025-27933 [MEDIUM] CWE-863 Mattermost allows members with permission to convert public channels to private and convert private to public
Mattermost allows members with permission to convert public channels to private and convert private to public
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public.
ghsaosv
CVE-2025-64641P4MEDIUM≥ 0, < 8.0.0-20251121122154-b57c297c6d72025-12-24
CVE-2025-64641 [MEDIUM] CWE-863 Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin
Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Ji
ghsaosv
CVE-2024-1402P4MEDIUM≥ 0, < 8.1.8≥ 9.2.0, < 9.2.4+1 more2024-02-09
CVE-2024-1402 [MEDIUM] CWE-400 Mattermost vulnerable to denial of service via large number of emoji reactions
Mattermost vulnerable to denial of service via large number of emoji reactions
Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post. Fetching posts wit
ghsaosv
CVE-2023-48732P4MEDIUM≥ 0, < 8.1.72024-01-02
CVE-2023-48732 [MEDIUM] CWE-200 Mattermost notified all users in the channel when using WebSockets to respond individually
Mattermost notified all users in the channel when using WebSockets to respond individually
Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.
ghsaosv
CVE-2023-47865P4MEDIUM≥ 0, < 8.1.42023-11-27
CVE-2023-47865 [MEDIUM] CWE-284 Mattermost Improper Access Control vulnerability
Mattermost Improper Access Control vulnerability
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled
ghsaosv
CVE-2024-1888P4MEDIUM≥ 9.4.0, < 9.4.2≥ 9.3.0, < 9.3.1+2 more2024-02-29
CVE-2024-1888 [MEDIUM] CWE-284 Mattermost fails to check the "invite_guest" permission
Mattermost fails to check the "invite_guest" permission
Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server
ghsaosv
CVE-2025-4573P4MEDIUM≥ 0, < 8.0.0-20250414112942-77892234944b2025-06-11
CVE-2025-4573 [MEDIUM] CWE-90 Mattermost allows authenticated administrator to execute LDAP search filter injection
Mattermost allows authenticated administrator to execute LDAP search filter injection
Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT
ghsaosv