cbcvebase.

Mattermost Server vulnerabilities

445 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41

Vulnerabilities

Page 21 of 23
CVE-2019-20883P4MEDIUMCVSS 4.3fixed in 5.8.02020-06-19
CVE-2019-20883 [MEDIUM] CVE-2019-20883: An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Use An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post.
nvd
CVE-2019-20879P4MEDIUMCVSS 4.3fixed in 4.10.7≥ 5.6.0, < 5.6.5+2 more2020-06-19
CVE-2019-20879 [MEDIUM] CWE-287 CVE-2019-20879: An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-ma An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.
nvd
CVE-2017-18910P4MEDIUMCVSS 4.3fixed in 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18910 [MEDIUM] CWE-732 CVE-2017-18910: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications ca An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links.
nvd
CVE-2017-18872P4MEDIUMCVSS 4.3fixed in 4.3.3≥ 4.4.0, < 4.4.32020-06-19
CVE-2017-18872 [MEDIUM] CWE-732 CVE-2017-18872: An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
nvd
CVE-2024-24774P4MEDIUMCVSS 4.1≤ 8.1.72024-02-09
CVE-2024-24774 [MEDIUM] CWE-863 CVE-2024-24774: Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues.
nvd
CVE-2026-8074P4LOWCVSS 3.8≥ 10.11.0, < 10.11.18≥ 11.7.0, < 11.7.12026-06-22
CVE-2026-8074 [LOW] CWE-863 CVE-2026-8074: Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission ch Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint.. Mattermost Advisory ID: MMSA-2026-00667
nvd
CVE-2026-9820P4LOWCVSS 3.8≥ 10.11.0, < 10.11.20≥ 11.7.0, < 11.7.32026-07-13
CVE-2026-9820 [LOW] CWE-862 CVE-2026-9820: Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671
nvd
CVE-2026-6334P4LOWCVSS 3.8≥ 10.11.0, < 10.11.14≥ 11.5.0, < 11.5.22026-05-18
CVE-2026-6334 [LOW] CWE-305 CVE-2026-6334: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding du Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a different client via a crafted token exchange request.. Mattermost Advisory ID: MMSA-2026-00570
nvd
CVE-2025-54499P4LOWCVSS 3.7≥ 10.5.0, < 10.5.11≥ 10.11.0, < 10.11.32025-10-16
CVE-2025-54499 [LOW] CWE-208 CVE-2025-54499: Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for s Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets
nvd
CVE-2025-13324P4LOWCVSS 3.7≥ 10.11.0, < 10.11.6≥ 10.12.0, < 10.12.3+1 more2025-12-17
CVE-2025-13324 [LOW] CWE-863 CVE-2025-13324: Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remo Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actio
nvd
CVE-2026-3472P4LOWCVSS 3.5≥ 10.11.0, < 10.11.19≥ 11.5.0, < 11.5.7+1 more2026-06-26
CVE-2026-3472 [LOW] CWE-693 CVE-2026-3472: Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply m Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown image syntax into tool result content rendered by a victim's client.. Matter
nvd
CVE-2026-22545P4LOWCVSS 3.5≥ 10.11.0, < 10.11.112026-03-16
CVE-2026-22545 [LOW] CWE-863 CVE-2026-22545: Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processin Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password without confirmation via falsely claiming a different auth provider.. Mattermost Advisory ID: MMSA-2026-00583
nvd
CVE-2024-29221P4LOWCVSS 3.8≥ 8.1.0, < 8.1.11≥ 9.3.0, < 9.3.3+2 more2024-04-05
CVE-2024-29221 [LOW] CWE-284 CVE-2024-29221: Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly remov
nvd
CVE-2025-3913P4LOWCVSS 3.8≥ 9.11.0, < 9.11.13≥ 10.5.0, < 10.5.4+2 more2025-05-29
CVE-2025-3913 [LOW] CWE-863 CVE-2025-3913: Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate permissions when changing team privacy settings, allowing team administrators without the 'invite user' permission to access and modify team invite IDs via the /api/v4/teams/:teamId/privacy endpoint.
nvd
CVE-2025-53971P4LOWCVSS 3.8≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.92025-08-21
CVE-2025-53971 [LOW] CWE-863 CVE-2025-53971: Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint.
nvd
CVE-2026-26230P4LOWCVSS 3.8≥ 10.11.0, < 10.11.112026-03-16
CVE-2026-26230 [LOW] CWE-863 CVE-2026-26230: Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the tea Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Mattermost Advisory ID: MMSA-2025-00531
nvd
CVE-2025-47700P4LOWCVSS 3.5≥ 10.5.0, < 10.5.92025-08-21
CVE-2025-47700 [LOW] CWE-918 CVE-2025-47700: Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions
nvd
CVE-2025-55074P4LOWCVSS 3.5≥ 10.5.0, < 10.5.12≥ 10.11.0, < 10.11.42025-11-18
CVE-2025-55074 [LOW] CWE-1426 CVE-2025-55074: Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects
nvd
CVE-2025-13352P4LOWCVSS 3.0≥ 10.11.0, < 10.11.72025-12-17
CVE-2025-13352 [LOW] CWE-1287 CVE-2025-13352: Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validat Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
nvd
CVE-2025-22449P4LOWCVSS 3.8≥ 9.11.0, < 9.11.62025-01-09
CVE-2025-22449 [LOW] CWE-863 CVE-2025-22449: Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, w Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.
nvd
Mattermost Server vulnerabilities | cvebase