Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 11 of 23
CVE-2017-18882P4MEDIUMCVSS 6.1fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18882 [MEDIUM] CWE-79 CVE-2017-18882: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenG
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.
nvd
CVE-2025-9084P4MEDIUMCVSS 6.1≥ 10.5.0, < 10.5.102025-09-15
CVE-2025-9084 [MEDIUM] CWE-601 CVE-2025-9084: Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers
Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs
nvd
CVE-2020-14452P4MEDIUMCVSS 5.3fixed in 5.21.02020-06-19
CVE-2020-14452 [MEDIUM] CWE-22 CVE-2020-14452: An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTT
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.
nvd
CVE-2016-11068P4MEDIUMCVSS 5.3fixed in 3.2.02020-06-19
CVE-2016-11068 [MEDIUM] CWE-74 CVE-2016-11068: An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via inje
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
nvd
CVE-2017-18902P4MEDIUMCVSS 5.3fixed in 3.10.3≥ 4.0.0, < 4.0.42020-06-19
CVE-2017-18902 [MEDIUM] CWE-200 CVE-2017-18902: An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.
nvd
CVE-2019-20867P4MEDIUMCVSS 5.3fixed in 5.11.02020-06-19
CVE-2019-20867 [MEDIUM] CVE-2019-20867: An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel
An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post.
nvd
CVE-2017-18896P4MEDIUMCVSS 5.3fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18896 [MEDIUM] CWE-732 CVE-2017-18896: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.
nvd
CVE-2023-1774P4MEDIUMCVSS 5.4fixed in 7.1.6v7.7.12023-03-31
CVE-2023-1774 [MEDIUM] CWE-862 CVE-2023-1774: When processing an email invite to a private channel on a team, Mattermost fails to validate the inv
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
nvd
CVE-2023-1777P4MEDIUMCVSS 5.3fixed in 7.1.6v7.7.1+1 more2023-03-31
CVE-2023-1777 [MEDIUM] CWE-200 CVE-2023-1777: Mattermost allows an attacker to request a preview of an existing message when creating a new messag
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
nvd
CVE-2023-5331P4MEDIUMCVSS 5.3fixed in 7.8.11≥ 8.0.0, < 8.0.3+1 more2023-10-09
CVE-2023-5331 [MEDIUM] CWE-862 CVE-2023-5331: Mattermost fails to properly check the creator of an attached file when adding the file to a draft p
Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.
nvd
CVE-2025-31947P4MEDIUMCVSS 5.3≥ 9.11.0, < 9.11.12≥ 10.4.0, < 10.4.5+2 more2025-05-15
CVE-2025-31947 [MEDIUM] CWE-645 CVE-2025-31947: Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
nvd
CVE-2017-18876P4MEDIUMCVSS 4.9fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18876 [MEDIUM] CWE-732 CVE-2017-18876: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for f
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
nvd
CVE-2026-3116P4MEDIUMCVSS 4.9≥ 10.11.0, < 10.11.12≥ 11.2.0, < 11.2.4+2 more2026-03-26
CVE-2026-3116 [MEDIUM] CWE-400 CVE-2026-3116: Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request
Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589
nvd
CVE-2018-21250P4MEDIUMCVSS 6.5fixed in 4.10.4≥ 5.1.0, < 5.1.2+1 more2020-06-19
CVE-2018-21250 [MEDIUM] CWE-400 CVE-2018-21250: An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attac
An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions.
nvd
CVE-2026-0997P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.10≥ 11.1.0, < 11.1.3+1 more2026-02-16
CVE-2026-0997 [MEDIUM] CWE-863 CVE-2026-0997: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoo
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via crafted API requests.. Mattermost Adv
nvd
CVE-2016-11063P4MEDIUMCVSS 6.1fixed in 3.5.12020-06-19
CVE-2016-11063 [MEDIUM] CWE-79 CVE-2016-11063: An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
nvd
CVE-2017-18881P4MEDIUMCVSS 6.1fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18881 [MEDIUM] CWE-79 CVE-2017-18881: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a g
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.
nvd
CVE-2017-18879P4MEDIUMCVSS 6.1fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18879 [MEDIUM] CWE-79 CVE-2017-18879: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.
nvd
CVE-2017-18893P4MEDIUMCVSS 6.1fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18893 [MEDIUM] CWE-79 CVE-2017-18893: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.
nvd
CVE-2017-18880P4MEDIUMCVSS 6.1fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18880 [MEDIUM] CWE-79 CVE-2017-18880: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.
nvd