cbcvebase.

Mattermost Server vulnerabilities

445 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41

Vulnerabilities

Page 20 of 23
CVE-2019-20890P4MEDIUMCVSS 4.3fixed in 5.7.02020-06-19
CVE-2019-20890 [MEDIUM] CVE-2019-20890: An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discov An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
nvd
CVE-2017-18890P4MEDIUMCVSS 4.3fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18890 [MEDIUM] CWE-20 CVE-2017-18890: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker t An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.
nvd
CVE-2016-11081P4MEDIUMCVSS 4.3fixed in 2.2.02020-06-19
CVE-2016-11081 [MEDIUM] CWE-200 CVE-2016-11081: An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to informatio An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser.
nvd
CVE-2019-20870P4MEDIUMCVSS 4.3fixed in 5.10.02020-06-19
CVE-2019-20870 [MEDIUM] CWE-20 CVE-2019-20870: An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appe An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited flag after changing a post's file ID.
nvd
CVE-2016-11065P4MEDIUMCVSS 4.3fixed in 3.3.02020-06-19
CVE-2016-11065 [MEDIUM] CWE-732 CVE-2016-11065: An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket featu An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.
nvd
CVE-2018-21255P4MEDIUMCVSS 4.3fixed in 5.1.02020-06-19
CVE-2018-21255 [MEDIUM] CWE-732 CVE-2018-21255: An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Chan An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel.
nvd
CVE-2018-21261P4MEDIUMCVSS 4.3≥ 4.6.0, < 4.6.3≥ 4.7.0, < 4.7.4+1 more2020-06-19
CVE-2018-21261 [MEDIUM] CWE-732 CVE-2018-21261: An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accide An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.
nvd
CVE-2024-1402P4MEDIUMCVSS 4.3≤ 8.1.7≥ 9.0.0, ≤ 9.1.4+1 more2024-02-09
CVE-2024-1402 [MEDIUM] CWE-400 CVE-2024-1402: Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit t Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post and to crash the server due to overloading when clients attemp
nvd
CVE-2023-48732P4MEDIUMCVSS 4.3fixed in 8.1.72024-01-02
CVE-2023-48732 [MEDIUM] CWE-200 CVE-2023-48732: Mattermost fails to scope the WebSocket response around notified users to a each user separately res Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.
nvd
CVE-2024-2446P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.10≥ 9.2.0, < 9.2.6+2 more2024-03-15
CVE-2024-2446 [MEDIUM] CWE-400 CVE-2024-2446: Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9. Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentions processed per message, allowing an authenticated attacker to crash the client applications of other users via large, crafted messages.
nvd
CVE-2023-49874P4MEDIUMCVSS 4.3≤ 7.8.14≥ 8.0.0, ≤ 8.1.5+3 more2023-12-12
CVE-2023-49874 [MEDIUM] CWE-284 CVE-2023-49874: Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook ru Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.
nvd
CVE-2024-1888P4MEDIUMCVSS 4.3fixed in 8.1.9≥ 9.2.0, < 9.2.5+2 more2024-02-29
CVE-2024-1888 [MEDIUM] CWE-284 CVE-2024-1888: Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a tea Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server
nvd
CVE-2025-4573P4MEDIUMCVSS 4.1≥ 9.11.0, < 9.11.14≥ 10.5.0, < 10.5.5+2 more2025-06-11
CVE-2025-4573 [MEDIUM] CWE-90 CVE-2025-4573: Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT /api/v4/ldap/groups/{remote_id}/link API when objectGUID
nvd
CVE-2026-8823P4LOWCVSS 3.8≥ 10.11.0, < 10.11.18≥ 11.7.0, < 11.7.12026-06-22
CVE-2026-8823 [LOW] CWE-863 CVE-2026-8823: Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669
nvd
CVE-2019-20860P4MEDIUMCVSS 5.5fixed in 5.9.4≥ 5.12.0, < 5.12.6+2 more2020-06-19
CVE-2019-20860 [MEDIUM] CVE-2019-20860: An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows rem An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.
nvd
CVE-2017-18878P4MEDIUMCVSS 4.3fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18878 [MEDIUM] CWE-732 CVE-2017-18878: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
nvd
CVE-2019-20878P4MEDIUMCVSS 4.3fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20878 [MEDIUM] CVE-2019-20878: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.
nvd
CVE-2016-11080P4MEDIUMCVSS 4.3fixed in 3.0.02020-06-19
CVE-2016-11080 [MEDIUM] CWE-732 CVE-2016-11080: An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Adm An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details.
nvd
CVE-2023-2281P4MEDIUMCVSS 4.3fixed in 7.9.02023-04-25
CVE-2023-2281 [MEDIUM] CWE-200 CVE-2023-2281: When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently co When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.
nvd
CVE-2023-50333P4MEDIUMCVSS 4.3fixed in 8.1.72024-01-02
CVE-2023-50333 [MEDIUM] CWE-284 CVE-2023-50333: Mattermost fails to update the permissions of the current session for a user who was just demoted to Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.
nvd
Mattermost Server vulnerabilities | cvebase