cbcvebase.

Mattermost Server vulnerabilities

445 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41

Vulnerabilities

Page 22 of 23
CVE-2023-3613P4LOWCVSS 3.5fixed in 7.8.6≥ 7.9.0, < 7.10.32023-07-17
CVE-2023-3613 [LOW] CWE-863 CVE-2023-3613: Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding user Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowing guest accounts to be added or invited to channels by default.
nvd
CVE-2023-3584P4LOWCVSS 3.1≥ 7.8.0, < 7.8.5≥ 7.10.0, < 7.10.32023-07-17
CVE-2023-3584 [LOW] CWE-863 CVE-2023-3584: Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team overr Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge of a Team Override Scheme ID to create a new team with said team override scheme.
nvd
CVE-2025-6227P4LOWCVSS 3.1≥ 9.11.0, < 9.11.17≥ 10.5.0, < 10.5.82025-07-18
CVE-2025-6227 [LOW] CWE-522 CVE-2025-6227: Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.
nvd
CVE-2018-21249P4LOWCVSS 3.7fixed in 5.3.02020-06-19
CVE-2018-21249 [LOW] CVE-2018-21249: An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing. An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing.
nvd
CVE-2024-23319P4LOWCVSS 3.5≤ 8.1.72024-02-09
CVE-2024-23319 [LOW] CWE-352 CVE-2024-23319: Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.
nvd
CVE-2026-20796P4LOWCVSS 3.1≥ 10.11.0, < 10.11.102026-02-13
CVE-2026-20796 [LOW] CWE-367 CVE-2026-20796: Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of d Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549
nvd
CVE-2024-21848P4LOWCVSS 3.1≥ 8.1.0, < 8.1.112024-04-05
CVE-2024-21848 [LOW] CWE-284 CVE-2024-21848: Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
nvd
CVE-2025-1792P4LOWCVSS 3.1≥ 9.11.0, < 9.11.13≥ 10.5.0, < 10.5.4+1 more2025-05-30
CVE-2025-1792 [LOW] CWE-863 CVE-2025-1792: Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce a Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
nvd
CVE-2024-4198P4LOWCVSS 2.7≥ 8.1.0, < 8.1.12≥ 9.5.0, < 9.5.3+1 more2024-04-26
CVE-2024-4198 [LOW] CWE-284 CVE-2024-4198: Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role c Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
nvd
CVE-2025-24866P4LOWCVSS 2.7≥ 9.11.0, < 9.11.92025-04-10
CVE-2025-24866 [LOW] CWE-863 CVE-2025-24866: Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits e Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
nvd
CVE-2026-3109P4LOWCVSS 2.2≥ 10.11.0, < 10.11.122026-03-26
CVE-2026-3109 [LOW] CWE-754 CVE-2026-3109: Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allo Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584
nvd
CVE-2023-3614P4LOWCVSS 3.3fixed in 7.8.7≥ 7.9.0, < 7.9.5+1 more2023-07-17
CVE-2023-3614 [LOW] CWE-400 CVE-2023-3614: Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significan Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file.
nvd
CVE-2023-27266P4LOWCVSS 2.7≥ 5.12.0, < 7.7.02023-02-27
CVE-2023-27266 [LOW] CWE-200 CVE-2023-27266: Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/u Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
nvd
CVE-2024-4195P4LOWCVSS 2.7≥ 8.1.0, < 8.1.12≥ 9.5.0, < 9.5.32024-04-26
CVE-2024-4195 [LOW] CWE-284 CVE-2024-4195: Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role c Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
nvd
CVE-2026-27769P4LOWCVSS 2.7≥ 10.11.0, < 10.11.132026-04-15
CVE-2026-27769 [LOW] CWE-862 CVE-2026-27769: Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the c Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory ID: MMSA-2026-00603
nvd
CVE-2025-14573P4LOWCVSS 2.7≥ 10.11.0, < 10.11.102026-02-16
CVE-2025-14573 [LOW] CWE-862 CVE-2025-14573: Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team setting Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561
nvd
CVE-2016-11077P4LOWCVSS 2.7fixed in 3.0.02020-06-19
CVE-2016-11077 [LOW] CWE-732 CVE-2016-11077: An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the Sys An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.
nvd
CVE-2023-27265P4LOWCVSS 2.7≥ 5.12.0, < 7.7.02023-02-27
CVE-2023-27265 [LOW] CWE-200 CVE-2023-27265: Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenera Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
nvd
CVE-2025-2570P4LOWCVSS 2.7≥ 9.11.0, < 9.11.12≥ 10.5.0, < 10.5.42025-05-15
CVE-2025-2570 [LOW] CWE-863 CVE-2025-2570: Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console.
nvd
CVE-2025-27538P4LOWCVSS 2.7≥ 9.11.0, < 9.11.10≥ 10.5.0, < 10.5.22025-04-16
CVE-2025-27538 [LOW] CWE-306 CVE-2025-27538: Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/use Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if those users have not set up MFA.
nvd
Mattermost Server vulnerabilities | cvebase