cbcvebase.

Mattermost Server vulnerabilities

445 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41

Vulnerabilities

Page 23 of 23
CVE-2024-1949P4LOWCVSS 2.6≥ 8.1.0, < 8.1.9≥ 9.4.0, < 9.4.22024-02-29
CVE-2024-1949 [LOW] CWE-200 CVE-2024-1949: A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authent A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.
nvd
CVE-2018-21260P4LOWCVSS 2.7≥ 4.6.0, < 4.6.3≥ 4.7.0, < 4.7.4+1 more2020-06-19
CVE-2018-21260 [LOW] CWE-200 CVE-2018-21260: An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were a An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.
nvd
CVE-2024-40884P4LOWCVSS 2.7≥ 9.5.0, < 9.5.8v9.10.02024-08-22
CVE-2024-40884 [LOW] CWE-284 CVE-2024-40884: Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allo Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
nvd
CVE-2025-27715P4LOWCVSS 2.7≥ 9.11.0, < 9.11.92025-03-21
CVE-2025-27715 [LOW] CWE-863 CVE-2025-27715: Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.
nvd
CVE-2023-3587P4LOWCVSS 2.7≥ 7.8.0, < 7.8.7≥ 7.10.0, < 7.10.32023-07-17
CVE-2023-3587 [LOW] CWE-862 CVE-2023-3587: Mattermost fails to properly show information in the UI, allowing a system admin to modify a board s Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions.
nvd
Mattermost Server vulnerabilities | cvebase