Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 13 of 23
CVE-2026-4646P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-22
CVE-2026-4646 [MEDIUM] CWE-1287 CVE-2026-4646: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to crash the plugin process via a crafted HTTP request to the PR details endpoint.. Mattermost Advisory ID: MMSA-2026-00638
nvd
CVE-2026-10103P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.20≥ 11.6.0, < 11.6.5+1 more2026-07-13
CVE-2026-10103 [MEDIUM] CWE-639 CVE-2026-10103: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post owne
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs in channels shared with that rem
nvd
CVE-2017-18907P4MEDIUMCVSS 6.1fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18907 [MEDIUM] CWE-79 CVE-2017-18907: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
nvd
CVE-2016-11083P4MEDIUMCVSS 6.1fixed in 2.2.02020-06-19
CVE-2016-11083 [MEDIUM] CWE-79 CVE-2016-11083: An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
nvd
CVE-2017-18897P4MEDIUMCVSS 6.1fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18897 [MEDIUM] CWE-601 CVE-2017-18897: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
nvd
CVE-2017-18904P4MEDIUMCVSS 6.1fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18904 [MEDIUM] CWE-79 CVE-2017-18904: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an u
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.
nvd
CVE-2016-11082P4MEDIUMCVSS 6.1fixed in 2.2.02020-06-19
CVE-2016-11082 [MEDIUM] CWE-79 CVE-2016-11082: An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
nvd
CVE-2021-37863P4MEDIUMCVSS 5.7≤ 6.02021-12-17
CVE-2021-37863 [MEDIUM] CWE-20 CVE-2021-37863: Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which all
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
nvd
CVE-2017-18898P4MEDIUMCVSS 5.3fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18898 [MEDIUM] CWE-404 CVE-2017-18898: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang.
nvd
CVE-2016-11067P4MEDIUMCVSS 5.3fixed in 3.2.02020-06-19
CVE-2016-11067 [MEDIUM] CWE-20 CVE-2016-11067: An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
nvd
CVE-2019-20877P4MEDIUMCVSS 5.3fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20877 [MEDIUM] CVE-2019-20877: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attac
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
nvd
CVE-2017-18901P4MEDIUMCVSS 5.3fixed in 3.10.3≥ 4.0.0, < 4.0.42020-06-19
CVE-2017-18901 [MEDIUM] CWE-200 CVE-2017-18901: An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON document.
nvd
CVE-2016-11062P4MEDIUMCVSS 5.3fixed in 3.5.12020-06-19
CVE-2016-11062 [MEDIUM] CWE-732 CVE-2016-11062: An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypass
An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
nvd
CVE-2019-20847P4MEDIUMCVSS 5.3fixed in 5.18.02020-06-19
CVE-2019-20847 [MEDIUM] CVE-2019-20847: An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSo
An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any channel.
nvd
CVE-2016-11070P4MEDIUMCVSS 5.4fixed in 3.1.02020-06-19
CVE-2016-11070 [MEDIUM] CWE-79 CVE-2016-11070: An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
nvd
CVE-2017-18905P4MEDIUMCVSS 5.3fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18905 [MEDIUM] CWE-613 CVE-2017-18905: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.
nvd
CVE-2025-8402P4MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+3 more2025-08-21
CVE-2025-8402 [MEDIUM] CWE-476 CVE-2025-8402: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.
nvd
CVE-2024-39839P4MEDIUMCVSS 4.3≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-39839 [MEDIUM] CWE-284 CVE-2024-39839: Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced b
nvd
CVE-2026-9162P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.18≥ 11.5.0, < 11.5.6+2 more2026-06-22
CVE-2026-9162 [MEDIUM] CWE-613 CVE-2026-9162: Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail t
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connections during global session revocation, which allows a user with an existing WebSocket connection to remain authenticated and continue receiving real-time events until the cached sessio
nvd
CVE-2024-5270P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.13≥ 9.5.0, < 9.5.4+2 more2024-05-26
CVE-2024-5270 [MEDIUM] CWE-284 CVE-2024-5270: Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch their authentication mail from SAML to email and possibly edit personal details that were otherwise non-editable and p
nvd