cbcvebase.

Mattermost Server vulnerabilities

445 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41

Vulnerabilities

Page 10 of 23
CVE-2026-2456P4MEDIUMCVSS 5.7≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-2456 [MEDIUM] CWE-789 CVE-2026-2456: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limi Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker to cause server memory exhaustion and denial of service via a malicious integration server that returns an arbitrarily large response when a user clicks an
nvd
CVE-2018-21257P4MEDIUMCVSS 5.3fixed in 5.1.02020-06-19
CVE-2018-21257 [MEDIUM] CWE-862 CVE-2018-21257: An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended acce An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.
nvd
CVE-2017-18919P4MEDIUMCVSS 5.3fixed in 3.6.32020-06-19
CVE-2017-18919 [MEDIUM] CWE-287 CVE-2017-18919: An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for u An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.
nvd
CVE-2023-6547P4MEDIUMCVSS 5.4≤ 8.1.5≥ 9.2.0, ≤ 9.2.12023-12-12
CVE-2023-6547 [MEDIUM] CWE-284 CVE-2023-6547: Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a u Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team.
nvd
CVE-2023-46701P4MEDIUMCVSS 5.3≤ 7.8.14≥ 8.0.0, ≤ 8.1.5+3 more2023-12-12
CVE-2023-46701 [MEDIUM] CWE-200 CVE-2023-46701: Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timel Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID
nvd
CVE-2025-9072P4MEDIUMCVSS 5.4≥ 10.5.0, < 10.5.10≥ 10.9.0, < 10.9.5+1 more2025-09-15
CVE-2025-9072 [MEDIUM] CWE-601 CVE-2025-9072: Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redi Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.
nvd
CVE-2026-4635P4MEDIUMCVSS 5.3≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-22
CVE-2026-4635 [MEDIUM] CWE-362 CVE-2026-4635: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation of persistent notification message between the server deleting existing persistent notifications and archiving the
nvd
CVE-2025-36530P4MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+2 more2025-08-21
CVE-2025-36530 [MEDIUM] CWE-22 CVE-2025-36530: Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.
nvd
CVE-2025-8023P4MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+2 more2025-08-21
CVE-2025-8023 [MEDIUM] CWE-22 CVE-2025-8023: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, which allows a system admin to perform path traversal attacks via malicious path components, potentially enabling malicious file placement outside intended directories.
nvd
CVE-2025-11794P4MEDIUMCVSS 4.9≥ 10.5.0, < 10.5.12≥ 10.11.0, < 10.11.4+1 more2025-11-14
CVE-2025-11794 [MEDIUM] CWE-200 CVE-2025-11794: Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and MFA secrets via the POST /api/v4/users/{user_id}/email/verify/member endpoint
nvd
CVE-2019-20844P4MEDIUMCVSS 6.5fixed in 5.9.7≥ 5.15.0, < 5.15.4+3 more2020-06-19
CVE-2019-20844 [MEDIUM] CWE-924 CVE-2019-20844: An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An at An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel.
nvd
CVE-2025-62690P4MEDIUMCVSS 6.1≥ 10.11.0, < 10.11.52025-12-17
CVE-2025-62690 [MEDIUM] CWE-601 CVE-2025-62690: Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allo Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.
nvd
CVE-2019-20875P4MEDIUMCVSS 5.3fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20875 [MEDIUM] CWE-287 CVE-2019-20875: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a pas An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
nvd
CVE-2018-21262P4HIGHCVSS 7.5fixed in 4.7.32020-06-19
CVE-2018-21262 [HIGH] CWE-20 CVE-2018-21262: An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.
nvd
CVE-2023-3586P4MEDIUMCVSS 5.4≥ 7.8.0, < 7.8.7≥ 7.9.0, < 7.9.5+1 more2023-07-17
CVE-2023-3586 [MEDIUM] CWE-863 CVE-2023-3586: Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration op Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared public Boards to remain accessible.
nvd
CVE-2024-45843P4MEDIUMCVSS 5.4≥ 9.5.0, < 9.5.92024-09-26
CVE-2024-45843 [MEDIUM] CWE-918 CVE-2024-45843: Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibab Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
nvd
CVE-2025-22445P4MEDIUMCVSS 5.3≥ 10.0.0, < 10.3.02025-01-09
CVE-2025-22445 [MEDIUM] CWE-754 CVE-2025-22445: Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.
nvd
CVE-2025-0503P4MEDIUMCVSS 5.3≥ 9.11.0, < 9.11.72025-02-14
CVE-2025-0503 [MEDIUM] CWE-754 CVE-2025-0503: Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
nvd
CVE-2026-9708P4MEDIUMCVSS 4.9≥ 10.11.0, < 10.11.20≥ 11.6.0, < 11.6.5+1 more2026-07-13
CVE-2026-9708 [MEDIUM] CWE-639 CVE-2026-9708: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.
nvd
CVE-2026-0998P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.10≥ 11.1.0, < 11.1.3+1 more2026-02-16
CVE-2026-0998 [MEDIUM] CWE-862 CVE-2026-0998: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoo Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom meetings as any user and overwrite arbitrary posts via direct API calls with manipulated user IDs and
nvd
Mattermost Server vulnerabilities | cvebase