Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 2 of 23
CVE-2025-1412P3HIGHCVSS 8.8≥ 9.11.0, < 9.11.7≥ 10.4.0, < 10.4.22025-02-24
CVE-2025-1412 [HIGH] CWE-384 CVE-2025-1412: Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when c
Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.
nvd
CVE-2017-18900P3CRITICALCVSS 9.8fixed in 3.10.3≥ 4.0.0, < 4.0.42020-06-19
CVE-2017-18900 [CRITICAL] CWE-74 CVE-2017-18900: An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injectio
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.
nvd
CVE-2025-9079P3HIGHCVSS 7.2≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+3 more2025-09-19
CVE-2025-9079 [HIGH] CWE-22 CVE-2025-9079: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows admin users to execute arbitrary code via malicious plugin upload to prepackaged plugins directory
nvd
CVE-2026-2454P3HIGHCVSS 8.6≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-2454 [HIGH] CWE-1287 CVE-2026-2454: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrect
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin. Mattermost Advisory ID: MMSA-2025-00537
nvd
CVE-2017-18912P3CRITICALCVSS 9.8fixed in 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18912 [CRITICAL] CWE-22 CVE-2017-18912: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker t
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.
nvd
CVE-2025-55070P3HIGHCVSS 7.5fixed in 11.0.02025-11-14
CVE-2025-55070 [HIGH] CWE-306 CVE-2025-55070: Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which a
Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events
nvd
CVE-2017-18885P3CRITICALCVSS 9.8fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18885 [CRITICAL] CWE-269 CVE-2017-18885: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
nvd
CVE-2017-18886P3HIGHCVSS 8.8fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18886 [HIGH] CWE-732 CVE-2017-18886: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of r
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
nvd
CVE-2023-3581P3HIGHCVSS 8.1≥ 7.8.0, < 7.8.7≥ 7.9.0, < 7.9.5+1 more2023-07-17
CVE-2023-3581 [HIGH] CWE-346 CVE-2023-3581: Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker
Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.
nvd
CVE-2026-28741P3HIGHCVSS 8.1≥ 10.11.0, < 10.11.13≥ 11.3.0, < 11.3.3+2 more2026-04-15
CVE-2026-28741 [HIGH] CWE-352 CVE-2026-28741: Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail t
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's authentication method via a CSRF attack by tricking a user into visiting a malicious page. Mattermost Advisory ID: MMSA-2026-00625
nvd
CVE-2026-5740P3HIGHCVSS 7.5≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-22
CVE-2026-5740 [HIGH] CWE-789 CVE-2026-5740: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unauthenticated remote attacker to crash the server process and cause a full service outage for all users via a crafted binary WebSocket message sent to the publ
nvd
CVE-2017-18883P3CRITICALCVSS 9.1fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18883 [CRITICAL] CWE-331 CVE-2017-18883: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAut
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
nvd
CVE-2017-18911P3CRITICALCVSS 9.1fixed in 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18911 [CRITICAL] CWE-295 CVE-2017-18911: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate v
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
nvd
CVE-2019-20859P3HIGHCVSS 7.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20859 [HIGH] CVE-2019-20859: An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via
An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
nvd
CVE-2026-6347P3HIGHCVSS 7.6≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-6347 [HIGH] CWE-200 CVE-2026-6347: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensiti
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server credentials via the plaintext values present in the exported plugin configuration.. Mattermost Advisory ID: MMSA-2026-006
nvd
CVE-2026-3473P3HIGHCVSS 7.1≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-22
CVE-2026-3473 [HIGH] CWE-639 CVE-2026-3473: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620
nvd
CVE-2018-21263P3HIGHCVSS 8.8fixed in 4.5.2≥ 4.6.0, < 4.6.2+1 more2020-06-19
CVE-2018-21263 [HIGH] CWE-287 CVE-2018-21263: An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authe
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.
nvd
CVE-2023-45316P3HIGHCVSS 8.8≤ 7.8.14≥ 8.0.0, ≤ 8.1.5+3 more2023-12-12
CVE-2023-45316 [HIGH] CWE-352 CVE-2023-45316: Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run
Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/ as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.
nvd
CVE-2018-21248P3HIGHCVSS 7.5fixed in 5.4.02020-06-19
CVE-2018-21248 [HIGH] CWE-522 CVE-2018-21248: An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous a
An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.
nvd
CVE-2017-18920P3CRITICALCVSS 9.8fixed in 3.6.22020-06-19
CVE-2017-18920 [CRITICAL] CVE-2017-18920: An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the
An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.
nvd