Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 14 of 23
CVE-2024-50052P4MEDIUMCVSS 4.3≥ 9.5.0, < 9.5.10≥ 9.10.0, < 9.10.3+1 more2024-10-29
CVE-2024-50052 [MEDIUM] CWE-862 CVE-2024-50052: Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
nvd
CVE-2026-22892P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.10≥ 11.0.0, < 11.1.3+1 more2026-02-13
CVE-2026-22892 [MEDIUM] CWE-863 CVE-2026-22892: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user per
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providi
nvd
CVE-2026-4265P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-4265 [MEDIUM] CWE-863 CVE-2026-4265: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-sp
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a team where they have permission and reusing the file metadata in a POST request to a different team. Matte
nvd
CVE-2025-13870P4MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.52025-12-02
CVE-2025-13870 [MEDIUM] CWE-306 CVE-2025-13870: Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when
Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
nvd
CVE-2025-3611P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.13≥ 10.5.0, < 10.5.4+1 more2025-05-30
CVE-2025-3611 [MEDIUM] CWE-863 CVE-2025-3611: Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No acce
nvd
CVE-2025-11776P4MEDIUMCVSS 4.3fixed in 11.0.02025-11-14
CVE-2025-11776 [MEDIUM] CWE-863 CVE-2025-11776: Mattermost versions <11 fail to properly restrict access to archived channel search API which allows
Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint
nvd
CVE-2024-41926P4MEDIUMCVSS 4.3≥ 9.5.0, < 9.5.7v9.9.02024-08-01
CVE-2024-41926 [MEDIUM] CWE-284 CVE-2024-41926: Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages a
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.
nvd
CVE-2026-9824P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.20≥ 11.6.0, < 11.6.5+1 more2026-07-13
CVE-2026-9824 [MEDIUM] CWE-862 CVE-2026-9824: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2
nvd
CVE-2026-6541P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.20≥ 11.6.0, < 11.6.5+1 more2026-07-13
CVE-2026-6541 [MEDIUM] CWE-639 CVE-2026-6541: Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric
Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-006
nvd
CVE-2026-28732P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-28732 [MEDIUM] CWE-863 CVE-2026-28732: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash co
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to
nvd
CVE-2026-28759P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-28759 [MEDIUM] CWE-863 CVE-2026-28759: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership
nvd
CVE-2026-3637P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-3637 [MEDIUM] CWE-862 CVE-2026-3637: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post update and patch endpoints.. Mattermost Advisory ID: MMSA-2026
nvd
CVE-2026-2457P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-2457 [MEDIUM] CWE-346 CVE-2026-2457: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint.. Mattermost Advisory ID: MMSA-2025-00569
nvd
CVE-2017-18892P4MEDIUMCVSS 6.1fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18892 [MEDIUM] CWE-116 CVE-2017-18892: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can ha
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.
nvd
CVE-2016-11073P4MEDIUMCVSS 6.1fixed in 3.0.02020-06-19
CVE-2016-11073 [MEDIUM] CWE-79 CVE-2016-11073: An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support sett
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
nvd
CVE-2017-18921P4MEDIUMCVSS 6.1fixed in 3.5.22020-06-19
CVE-2017-18921 [MEDIUM] CWE-79 CVE-2017-18921: An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an
An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.
nvd
CVE-2017-18877P4MEDIUMCVSS 6.1≥ 4.1.0, < 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18877 [MEDIUM] CWE-79 CVE-2017-18877: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
nvd
CVE-2016-11079P4MEDIUMCVSS 6.1fixed in 3.0.02020-06-19
CVE-2016-11079 [MEDIUM] CWE-79 CVE-2016-11079: An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
nvd
CVE-2016-11071P4MEDIUMCVSS 6.1fixed in 3.1.02020-06-19
CVE-2016-11071 [MEDIUM] CWE-79 CVE-2016-11071: An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
nvd
CVE-2017-18891P4MEDIUMCVSS 6.1fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18891 [MEDIUM] CWE-601 CVE-2017-18891: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing beca
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
nvd