Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 1 of 23
CVE-2025-12421P2CRITICALCVSS 9.9≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-11-27
CVE-2025-12421 [CRITICAL] CWE-303 CVE-2025-12421: Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods
nvd
CVE-2025-12419P2CRITICALCVSS 9.9≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-11-27
CVE-2025-12419 [CRITICAL] CWE-303 CVE-2025-12419: Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail
Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow.
nvd
CVE-2025-4981P2CRITICALCVSS 9.9≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-20
CVE-2025-4981 [CRITICAL] CWE-427 CVE-2025-4981: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code
nvd
CVE-2025-25279P2HIGHCVSS 7.5≥ 9.11.0, < 9.11.8≥ 10.2.0, < 10.2.3+2 more2025-02-24
CVE-2025-25279 [HIGH] CWE-22 CVE-2025-25279: Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to p
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.
nvd
CVE-2026-4858P2CRITICALCVSS 9.9≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-21
CVE-2026-4858 [CRITICAL] CWE-22 CVE-2026-4858: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640
nvd
CVE-2024-2450P3HIGHCVSS 8.8≥ 8.1.0, < 8.1.10≥ 9.2.0, < 9.2.6+3 more2024-03-15
CVE-2024-2450 [HIGH] CWE-287 CVE-2024-2450: Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.
nvd
CVE-2026-3108P3HIGHCVSS 8.8≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+2 more2026-03-26
CVE-2026-3108 [HIGH] CWE-150 CVE-2026-3108: Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail t
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences that enable screen manipulation, fake prompts, and cli
nvd
CVE-2025-14273P3HIGHCVSS 8.3≥ 10.11.0, < 10.11.8≥ 10.12.0, < 10.12.4+2 more2025-12-22
CVE-2025-14273 [HIGH] CWE-303 CVE-2025-14273: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST
nvd
CVE-2025-25068P3HIGHCVSS 8.8≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+2 more2025-03-21
CVE-2025-25068 [HIGH] CWE-306 CVE-2025-25068: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to e
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.
nvd
CVE-2025-25274P3HIGHCVSS 8.8≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+1 more2025-03-21
CVE-2025-25274 [HIGH] CWE-863 CVE-2025-25274: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command ex
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.
nvd
CVE-2017-18915P3CRITICALCVSS 9.8≥ 3.6.0, < 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18915 [CRITICAL] CWE-276 CVE-2017-18915: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a se
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.
nvd
CVE-2016-11074P3CRITICALCVSS 9.8fixed in 3.0.02020-06-19
CVE-2016-11074 [CRITICAL] CWE-287 CVE-2016-11074: An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
nvd
CVE-2017-18888P3CRITICALCVSS 9.8fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18888 [CRITICAL] CWE-89 CVE-2017-18888: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
nvd
CVE-2022-1384P3HIGHCVSS 8.8fixed in 6.5.02022-04-19
CVE-2022-1384 [HIGH] CWE-477 CVE-2022-1384: Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is ins
Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.
nvd
CVE-2026-6346P3HIGHCVSS 8.7≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-6346 [HIGH] CWE-200 CVE-2026-6346: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensiti
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermost System Admin or any party with access to a support packet to obtain sensitive credentials in plaintext via downloading a support packet from the System C
nvd
CVE-2025-58073P3HIGHCVSS 8.1≥ 10.5.0, < 10.5.11≥ 10.10.0, < 10.10.3+1 more2025-10-16
CVE-2025-58073 [HIGH] CWE-862 CVE-2025-58073: Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state.
nvd
CVE-2025-58075P3HIGHCVSS 8.1≥ 10.5.0, < 10.5.11≥ 10.10.0, < 10.10.3+1 more2025-10-16
CVE-2025-58075 [HIGH] CWE-862 CVE-2025-58075: Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState
nvd
CVE-2017-18908P3CRITICALCVSS 9.8fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18908 [CRITICAL] CWE-287 CVE-2017-18908: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset reque
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.
nvd
CVE-2023-6458P3CRITICALCVSS 9.8fixed in 7.8.14≥ 8.0.0, < 8.1.5+2 more2023-12-06
CVE-2023-6458 [CRITICAL] CWE-74 CVE-2023-6458: Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing
Mattermost webapp fails to validate route parameters in//channels/ allowing an attacker to perform a client-side path traversal.
nvd
CVE-2023-2515P3HIGHCVSS 8.8fixed in 7.1.8≥ 7.2.0, < 7.7.4+2 more2023-05-12
CVE-2023-2515 [HIGH] CWE-863 CVE-2023-2515: Mattermost fails to restrict a user with permissions to edit other users and to create personal acce
Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin
nvd
1 / 23Next →