Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 16 of 23
CVE-2026-2458P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-2458 [MEDIUM] CWE-862 CVE-2026-2458: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validat
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel search API endpoint.. Mattermost Advisory ID: MMSA-2025-00568
nvd
CVE-2026-24692P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-24692 [MEDIUM] CWE-863 CVE-2026-24692: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554
nvd
CVE-2025-41436P4MEDIUMCVSS 4.3fixed in 11.0.02025-11-14
CVE-2025-41436 [MEDIUM] CWE-863 CVE-2025-41436: Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setti
Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads
nvd
CVE-2026-4055P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.17≥ 11.5.0, < 11.5.5+1 more2026-05-21
CVE-2026-4055 [MEDIUM] CWE-863 CVE-2026-4055: Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the t
Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when creating a playbook run which allows an authenticated team member to create runs in teams where they lack permission via specifying a different team ID in the run creation API request. Mattermost Advisory ID: MMSA-2026-00629
nvd
CVE-2026-6341P4MEDIUMCVSS 4.3≥ 10.13.0, ≤ 10.13.11≥ 11.1.0, ≤ 11.1.5+1 more2026-05-18
CVE-2026-6341 [MEDIUM] CWE-863 CVE-2026-6341: Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which g
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which groups the user can create issues or attach comments to which allows a user that is member of multiple groups to create issues to a locked group via direct API requests. Mattermost Advisory ID: MMSA-2026-00602
nvd
CVE-2026-6342P4MEDIUMCVSS 4.3≥ 10.13.0, ≤ 10.13.11≥ 11.1.0, ≤ 11.1.5+1 more2026-05-18
CVE-2026-6342 [MEDIUM] CWE-863 CVE-2026-6342: Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid na
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allows plugin users to create subscriptions to groups that were not whitelisted via creating groups that share the same prefix as a whitelisted group. Mattermost Advisory ID: MMSA-2026-00601
nvd
CVE-2026-4286P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.14≥ 11.5.0, < 11.5.22026-05-18
CVE-2026-4286 [MEDIUM] CWE-863 CVE-2026-4286: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if was being cha
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing manage members restriction via PUT api. Mattermost Advisory ID: MMSA-2025-00552
nvd
CVE-2026-4273P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.14≥ 11.5.0, < 11.5.22026-05-18
CVE-2026-4273 [MEDIUM] CWE-863 CVE-2026-4273: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken d
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token via sending a crafted invite confirmation with a RefreshedToken matching
nvd
CVE-2016-11084P4MEDIUMCVSS 6.1fixed in 2.1.02020-06-19
CVE-2016-11084 [MEDIUM] CWE-352 CVE-2016-11084: An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
nvd
CVE-2017-18914P4MEDIUMCVSS 5.3fixed in 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18914 [MEDIUM] CWE-754 CVE-2017-18914: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can oc
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist.
nvd
CVE-2019-20872P4MEDIUMCVSS 5.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20872 [MEDIUM] CWE-918 CVE-2019-20872: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
nvd
CVE-2022-1385P4MEDIUMCVSS 4.6fixed in 6.5.02022-04-19
CVE-2022-1385 [MEDIUM] CWE-664 CVE-2022-1385: Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action
Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.
nvd
CVE-2026-3495P4MEDIUMCVSS 4.8≥ 10.11.0, < 10.11.14≥ 11.5.0, < 11.5.22026-05-18
CVE-2026-3495 [MEDIUM] CWE-79 CVE-2026-3495: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could c
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-00622
nvd
CVE-2022-1332P4MEDIUMCVSS 4.3≥ 5.37.0, < 5.37.9≥ 6.2.0, < 6.2.5+2 more2022-04-13
CVE-2022-1332 [MEDIUM] CWE-200 CVE-2022-1332: One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, wh
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.
nvd
CVE-2024-32046P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.12≥ 9.4.0, < 9.4.5+2 more2024-04-26
CVE-2024-32046 [MEDIUM] CWE-200 CVE-2024-32046: Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remov
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
nvd
CVE-2023-6727P4MEDIUMCVSS 4.3≤ 8.1.5≥ 9.2.0, ≤ 9.2.12023-12-12
CVE-2023-6727 [MEDIUM] CWE-200 CVE-2023-6727: Mattermost fails to perform correct authorization checks when creating a playbook action, allowing u
Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some playbook information, like the name, can be leaked.
nvd
CVE-2024-23488P4MEDIUMCVSS 4.3fixed in 8.1.9≥ 9.0.0, < 9.4.22024-02-29
CVE-2024-23488 [MEDIUM] CWE-284 CVE-2024-23488: Mattermost fails to properly restrict the access of files attached to posts in an archived channel,
Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled.
nvd
CVE-2026-25783P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-25783 [MEDIUM] CWE-1287 CVE-2026-25783: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validat
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586
nvd
CVE-2024-43780P4MEDIUMCVSS 4.3≥ 9.5.0, < 9.5.8≥ 9.8.0, < 9.8.3+2 more2024-08-22
CVE-2024-43780 [MEDIUM] CWE-284 CVE-2024-43780: Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissio
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
nvd
CVE-2026-25780P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-25780 [MEDIUM] CWE-789 CVE-2026-25780: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory all
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted DOC file.. Mattermost Advisory ID: MMSA-2026-00581
nvd