Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 18 of 23
CVE-2025-2571P4MEDIUMCVSS 4.2≥ 9.11.0, < 9.11.13≥ 10.5.0, < 10.5.4+2 more2025-05-30
CVE-2025-2571 [MEDIUM] CWE-303 CVE-2025-2571: Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
nvd
CVE-2017-18873P4MEDIUMCVSS 5.3fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18873 [MEDIUM] CWE-20 CVE-2017-18873: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post.
nvd
CVE-2018-21254P4MEDIUMCVSS 4.3fixed in 5.1.02020-06-19
CVE-2018-21254 [MEDIUM] CWE-732 CVE-2018-21254: An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access cont
An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.
nvd
CVE-2018-21256P4MEDIUMCVSS 4.3fixed in 5.1.02020-06-19
CVE-2018-21256 [MEDIUM] CWE-732 CVE-2018-21256: An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended acce
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command.
nvd
CVE-2023-3585P4MEDIUMCVSS 4.3fixed in 7.8.7≥ 7.9.0, < 7.9.5+1 more2023-07-17
CVE-2023-3585 [MEDIUM] CWE-400 CVE-2023-3585: Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.
nvd
CVE-2024-1953P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.9≥ 9.2.0, < 9.2.5+2 more2024-02-29
CVE-2024-1953 [MEDIUM] CWE-400 CVE-2024-1953: Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to li
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.
nvd
CVE-2023-3577P4MEDIUMCVSS 4.3≥ 7.8.0, < 7.8.7≥ 7.10.0, < 7.10.32023-07-17
CVE-2023-3577 [MEDIUM] CWE-918 CVE-2023-3577: Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog,
Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an attacker to perform a limited blind SSRF.
nvd
CVE-2024-1887P4MEDIUMCVSS 4.3fixed in 8.1.9≥ 9.2.0, < 9.2.5+1 more2024-02-29
CVE-2024-1887 [MEDIUM] CWE-284 CVE-2024-1887: Mattermost fails to check if compliance export is enabled when fetching posts of public channels all
Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the public channel to fetch the posts, which will not be audited in the compliance export.
nvd
CVE-2024-24776P4MEDIUMCVSS 4.3≤ 8.1.72024-02-09
CVE-2024-24776 [MEDIUM] CWE-284 CVE-2024-24776: Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count A
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.
nvd
CVE-2024-34029P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.13≥ 9.5.0, < 9.5.4+1 more2024-05-26
CVE-2024-34029 [MEDIUM] CWE-200 CVE-2024-34029: Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper auth
Mattermost versions 9.5.x /channels//link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if the user has no access to the team.
nvd
CVE-2024-52032P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.3v10.0.02024-11-09
CVE-2024-52032 [MEDIUM] CWE-200 CVE-2024-52032: Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when
Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, when Elasticsearch v8 was enabled.
nvd
CVE-2025-24526P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.8≥ 10.1.0, < 10.1.4+3 more2025-02-24
CVE-2025-24526 [MEDIUM] CWE-863 CVE-2025-24526: Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <
Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it
nvd
CVE-2025-2564P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-16
CVE-2025-2564 [MEDIUM] CWE-863 CVE-2025-2564: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce th
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.
nvd
CVE-2025-27571P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-16
CVE-2025-27571 [MEDIUM] CWE-863 CVE-2025-27571: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Us
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived Channels" configuration when fetching channel metadata of a post from archived channels, which allows authenticated users to access such information when a channel is archived.
nvd
CVE-2026-26246P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-26246 [MEDIUM] CWE-789 CVE-2026-26246: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory all
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted PSD file. Mattermost Advisory ID: MMSA-2026-00572
nvd
CVE-2026-2578P4MEDIUMCVSS 4.3≥ 11.3.0, < 11.3.12026-03-16
CVE-2026-2578 [MEDIUM] CWE-201 CVE-2026-2578: Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts durin
Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579
nvd
CVE-2025-24920P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+2 more2025-03-21
CVE-2025-24920 [MEDIUM] CWE-863 CVE-2025-24920: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to r
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels
nvd
CVE-2025-47870P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+2 more2025-08-21
CVE-2025-47870 [MEDIUM] CWE-306 CVE-2025-47870: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.
nvd
CVE-2025-3227P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-20
CVE-2025-3227 [MEDIUM] CWE-863 CVE-2025-3227: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run p
nvd
CVE-2025-3446P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.12≥ 10.4.0, < 10.4.5+2 more2025-05-15
CVE-2025-3446 [MEDIUM] CWE-863 CVE-2025-3446: Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct permissions which allows authenticated users who only have permission to invite non-guest users to a team to add guest users to that team via the API to add a single user to a team.
nvd