cbcvebase.

Mattermost Server vulnerabilities

445 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41

Vulnerabilities

Page 15 of 23
CVE-2017-18913P4MEDIUMCVSS 6.1fixed in 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18913 [MEDIUM] CWE-79 CVE-2017-18913: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a lin An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.
nvd
CVE-2023-1421P4MEDIUMCVSS 6.1≥ 5.32.0, < 7.7.02023-03-15
CVE-2023-1421 [MEDIUM] CWE-79 CVE-2023-1421: A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
nvd
CVE-2020-14457P4MEDIUMCVSS 5.3fixed in 5.20.02020-06-19
CVE-2020-14457 [MEDIUM] CVE-2020-14457: An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka MMSA-2020-0012.
nvd
CVE-2017-18887P4MEDIUMCVSS 5.3fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18887 [MEDIUM] CWE-200 CVE-2017-18887: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team c An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
nvd
CVE-2016-11075P4MEDIUMCVSS 5.3fixed in 3.0.02020-06-19
CVE-2016-11075 [MEDIUM] CWE-200 CVE-2016-11075: An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive i An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
nvd
CVE-2024-54682P4MEDIUMCVSS 4.9≥ 9.5.0, < 9.5.13≥ 9.11.0, < 9.11.5+2 more2024-12-16
CVE-2024-54682 [MEDIUM] CWE-409 CVE-2024-54682: Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to li Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.
nvd
CVE-2024-48872P4MEDIUMCVSS 4.8≥ 9.5.0, < 9.5.13≥ 9.11.0, < 9.11.5+2 more2024-12-16
CVE-2024-48872 [MEDIUM] CWE-362 CVE-2024-48872: Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail t Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requ
nvd
CVE-2024-36250P4MEDIUMCVSS 4.8≥ 9.5.0, < 9.5.11≥ 9.11.0, < 9.11.32024-11-09
CVE-2024-36250 [MEDIUM] CWE-303 CVE-2024-36250: Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against repla Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
nvd
CVE-2024-46872P4MEDIUMCVSS 4.6≥ 9.5.0, ≤ 9.5.9≥ 9.10.0, ≤ 9.10.2+1 more2024-10-29
CVE-2024-46872 [MEDIUM] CWE-352 CVE-2024-46872: Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
nvd
CVE-2025-10545P4MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.11≥ 10.11.0, < 10.11.32025-10-16
CVE-2025-10545 [MEDIUM] CWE-863 CVE-2025-10545: Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permi Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint
nvd
CVE-2025-41443P4MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.11≥ 10.11.0, < 10.11.32025-10-16
CVE-2025-41443 [MEDIUM] CWE-862 CVE-2025-41443: Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permi Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_id}/channels/ids` endpoint
nvd
CVE-2024-42000P4MEDIUMCVSS 4.3≥ 9.5.0, < 9.5.10≥ 9.10.0, < 9.10.3+2 more2024-11-09
CVE-2024-42000 [MEDIUM] CWE-863 CVE-2024-42000: Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels which allows a User or System Manager, with "Read Groups" permission but with no access for channels to retrieve details about private channels that they were not a member of by sending a request to /
nvd
CVE-2024-41162P4MEDIUMCVSS 4.3≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-41162 [MEDIUM] CWE-284 CVE-2024-41162: Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disall Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.
nvd
CVE-2025-41423P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.11≥ 10.4.0, < 10.4.3+1 more2025-04-24
CVE-2025-41423 [MEDIUM] CWE-863 CVE-2025-41423: Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.
nvd
CVE-2026-3636P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-22
CVE-2026-3636 [MEDIUM] CWE-200 CVE-2026-3636: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team member data when returned via API to users without elevated permissions which allows a user without permissions to get data about team members roles via invoking various team API endpoints.. Mattermost Advisory ID: MMSA-2026-00626
nvd
CVE-2026-0999P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.10≥ 11.1.0, < 11.1.3+1 more2026-02-16
CVE-2026-0999 [MEDIUM] CWE-303 CVE-2026-0999: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548
nvd
CVE-2026-2463P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-2463 [MEDIUM] CWE-862 CVE-2026-2463: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite ID Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565
nvd
CVE-2025-13767P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.8≥ 10.12.0, < 10.12.4+2 more2025-12-24
CVE-2025-13767 [MEDIUM] CWE-863 CVE-2025-13767: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
nvd
CVE-2026-4053P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.14≥ 11.5.0, < 11.5.22026-05-15
CVE-2026-4053 [MEDIUM] CWE-672 CVE-2026-4053: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on n Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631
nvd
CVE-2026-2455P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-2455 [MEDIUM] CWE-918 CVE-2026-2455: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation which allows an attacker to perform SSRF attacks against internal services via IPv4-mapped IPv6 literals (e.g., [::ffff:127.0.0.1]).. Mattermost Advisory ID: MMSA-2026-00585
nvd
Mattermost Server vulnerabilities | cvebase