Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 12 of 23
CVE-2024-2445P4MEDIUMCVSS 6.1≥ 8.1.0, < 8.1.10≥ 9.2.0, < 9.2.6+2 more2024-03-15
CVE-2024-2445 [MEDIUM] CWE-74 CVE-2024-2445: Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9
Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server.
nvd
CVE-2017-18899P4MEDIUMCVSS 5.3fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18899 [MEDIUM] CWE-770 CVE-2017-18899: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
nvd
CVE-2019-20876P4MEDIUMCVSS 5.4fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20876 [MEDIUM] CVE-2019-20876: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deact
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
nvd
CVE-2019-20866P4MEDIUMCVSS 5.3fixed in 5.12.02020-06-19
CVE-2019-20866 [MEDIUM] CWE-444 CVE-2019-20866: An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than
An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address in an IP packet header, for obtaining IP address information was mishandled.
nvd
CVE-2017-18895P4MEDIUMCVSS 5.3fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18895 [MEDIUM] CWE-200 CVE-2017-18895: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via a REST API version 4 endpoint.
nvd
CVE-2021-37862P4MEDIUMCVSS 5.4≤ 6.02021-12-17
CVE-2021-37862 [MEDIUM] CWE-754 CVE-2021-37862: Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, whi
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.
nvd
CVE-2016-11076P4MEDIUMCVSS 5.3fixed in 3.0.02020-06-19
CVE-2016-11076 [MEDIUM] CWE-295 CVE-2016-11076: An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
nvd
CVE-2019-20884P4MEDIUMCVSS 5.3fixed in 5.8.02020-06-19
CVE-2019-20884 [MEDIUM] CVE-2019-20884: An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a
An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post.
nvd
CVE-2019-20869P4MEDIUMCVSS 5.3fixed in 4.10.9≥ 5.7.0, < 5.7.3+3 more2020-06-19
CVE-2019-20869 [MEDIUM] CVE-2019-20869: An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member c
An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel.
nvd
CVE-2019-20882P4MEDIUMCVSS 5.3fixed in 5.8.02020-06-19
CVE-2019-20882 [MEDIUM] CWE-276 CVE-2019-20882: An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
nvd
CVE-2019-20889P4MEDIUMCVSS 5.3≥ 4.10.0, < 4.10.5≥ 5.5.0, < 5.5.2+2 more2020-06-19
CVE-2019-20889 [MEDIUM] CWE-276 CVE-2019-20889: An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles per
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.
nvd
CVE-2026-3113P4MEDIUMCVSS 5.5≥ 10.11.0, < 10.11.12≥ 11.2.0, < 11.2.4+2 more2026-03-26
CVE-2026-3113 [MEDIUM] CWE-732 CVE-2026-3113: Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail t
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. Mattermost Advisory ID: MMSA-2026-00593
nvd
CVE-2023-6459P4MEDIUMCVSS 5.3fixed in 7.8.14≥ 8.0.0, < 8.1.52023-12-06
CVE-2023-6459 [MEDIUM] CWE-200 CVE-2023-6459: Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Sin
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.
nvd
CVE-2017-18875P4MEDIUMCVSS 4.9fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18875 [MEDIUM] CWE-732 CVE-2017-18875: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for f
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
nvd
CVE-2017-18918P4MEDIUMCVSS 4.9≥ 3.6.0, < 3.6.5≥ 3.7.0, < 3.7.32020-06-19
CVE-2017-18918 [MEDIUM] CWE-295 CVE-2017-18918: An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can plac
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.
nvd
CVE-2024-42497P4MEDIUMCVSS 4.9≥ 9.5.0, < 9.5.8≥ 9.8.0, < 9.8.3+2 more2024-08-22
CVE-2024-42497 [MEDIUM] CWE-284 CVE-2024-42497: Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properl
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.
nvd
CVE-2025-32093P4MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-14
CVE-2025-32093 [MEDIUM] CWE-863 CVE-2025-32093: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain op
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system administrators via improper permission validation.
nvd
CVE-2026-27659P4MEDIUMCVSS 4.6≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+2 more2026-03-25
CVE-2026-27659 [MEDIUM] CWE-352 CVE-2026-27659: Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail t
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate CSRF tokens in the /api/v4/access_control_policies/{policy_id}/activate endpoint, which allows an attacker to trick an admin into changing access control policy active status via a crafted request.. Mattermost Advisory ID: MMSA-202
nvd
CVE-2025-6465P4MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.9≥ 10.8.0, < 10.8.4+2 more2025-08-21
CVE-2025-6465 [MEDIUM] CWE-22 CVE-2025-6465: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.
nvd
CVE-2024-36241P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.13≥ 9.5.0, < 9.5.4+1 more2024-05-26
CVE-2024-36241 [MEDIUM] CWE-284 CVE-2024-36241: Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command
nvd