Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 17 of 23
CVE-2024-9155P4MEDIUMCVSS 4.3≥ 9.5.0, < 9.5.9≥ 9.9.0, < 9.9.3+1 more2024-09-26
CVE-2024-9155 [MEDIUM] CWE-863 CVE-2024-9155: Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channel
Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.
nvd
CVE-2024-34152P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.13≥ 9.5.0, < 9.5.4+1 more2024-05-26
CVE-2024-34152 [MEDIUM] CWE-284 CVE-2024-34152: Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL query request to the server
nvd
CVE-2025-2527P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.12≥ 10.5.0, < 10.5.32025-05-15
CVE-2025-2527 [MEDIUM] CWE-863 CVE-2025-2527: Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissio
Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.
nvd
CVE-2024-47145P4MEDIUMCVSS 4.3≥ 9.5.0, < 9.5.92024-09-26
CVE-2024-47145 [MEDIUM] CWE-284 CVE-2024-47145: Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewi
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
nvd
CVE-2025-3228P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-20
CVE-2025-3228 [MEDIUM] CWE-863 CVE-2025-3228: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run.
nvd
CVE-2024-29215P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.13≥ 9.5.0, < 9.5.4+2 more2024-05-26
CVE-2024-29215 [MEDIUM] CWE-284 CVE-2024-29215: Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and running a slash command as a playbook task command.
nvd
CVE-2025-2424P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.10≥ 10.5.0, < 10.5.22025-04-14
CVE-2025-2424 [MEDIUM] CWE-863 CVE-2025-2424: Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
nvd
CVE-2025-1472P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.92025-03-19
CVE-2025-1472 [MEDIUM] CWE-863 CVE-2025-1472: Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which
Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
nvd
CVE-2026-3115P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+2 more2026-03-26
CVE-2026-3115 [MEDIUM] CWE-863 CVE-2026-3115: Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail t
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Mattermost Advisory ID: MMSA-2026-00594
nvd
CVE-2025-24839P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-16
CVE-2025-24839 [MEDIUM] CWE-863 CVE-2025-24839: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler po
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override property to a post via the Wrangler plugin, provided both the AI and Wrangler plugins are enabled.
nvd
CVE-2025-12559P4MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-11-27
CVE-2025-12559 [MEDIUM] CWE-200 CVE-2025-12559: Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
nvd
CVE-2026-1629P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.112026-03-16
CVE-2026-1629 [MEDIUM] CWE-672 CVE-2026-1629: Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user
Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previously cached permalink previews until cache reset or relogin.. Mattermost Advisory ID: MMSA-2026-00580
nvd
CVE-2025-4128P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.14≥ 10.5.0, < 10.5.52025-06-11
CVE-2025-4128 [MEDIUM] CWE-863 CVE-2025-4128: Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team
Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
nvd
CVE-2025-11777P4MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.12≥ 10.11.0, < 10.11.42025-11-13
CVE-2025-11777 [MEDIUM] CWE-863 CVE-2025-11777: Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint
nvd
CVE-2026-6343P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-6343 [MEDIUM] CWE-863 CVE-2026-6343: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/pri
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public playbooks via /get.. Mattermost Advisory ID: MMSA-2026-00591
nvd
CVE-2026-2461P4MEDIUMCVSS 4.3fixed in 10.11.11≥ 11.0.0, ≤ 11.0.3+2 more2026-03-16
CVE-2026-2461 [MEDIUM] CWE-639 CVE-2026-2461: Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks o
Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559
nvd
CVE-2025-14350P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.10≥ 11.1.0, < 11.1.3+1 more2026-02-16
CVE-2025-14350 [MEDIUM] CWE-862 CVE-2025-14350: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and observing the channel_mentions property in the API response. Mattermost Advis
nvd
CVE-2025-12756P4MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-12-01
CVE-2025-12756 [MEDIUM] CWE-863 CVE-2025-12756: Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.
nvd
CVE-2026-26304P4MEDIUMCVSS 4.3≥ 11.2.0, < 11.2.3≥ 11.3.0, < 11.3.12026-03-16
CVE-2026-26304 [MEDIUM] CWE-863 CVE-2026-26304: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empt
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, which allows team members to create unauthorized runs via the playbook run API. Mattermost Advisory ID: MMSA-2025-00542
nvd
CVE-2025-9078P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+3 more2025-09-15
CVE-2025-9078 [MEDIUM] CWE-328 CVE-2025-9078: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to properly validate cache keys for link metadata which allows authenticated users to access unauthorized posts and poison link previews via hash collision attacks on FNV-1 hashing
nvd