Mattermost Server vulnerabilities
389 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
389
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH74MEDIUM266LOW34
Vulnerabilities
Page 3 of 20
CVE-2025-13767MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.8≥ 10.12.0, < 10.12.4+2 more2025-12-24
CVE-2025-13767 [MEDIUM] CWE-863 CVE-2025-13767: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
nvd
CVE-2025-64641MEDIUMCVSS 4.1≥ 10.11.0, < 10.11.8≥ 10.12.0, < 10.12.4+2 more2025-12-24
CVE-2025-64641 [MEDIUM] CWE-863 CVE-2025-64641: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts
nvd
CVE-2025-14273HIGHCVSS 8.3≥ 10.11.0, < 10.11.8≥ 10.12.0, < 10.12.4+2 more2025-12-22
CVE-2025-14273 [HIGH] CWE-303 CVE-2025-14273: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST
nvd
CVE-2025-12689MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.7≥ 10.12.0, < 10.12.3+1 more2025-12-17
CVE-2025-12689 [MEDIUM] CWE-1287 CVE-2025-12689: Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.
nvd
CVE-2025-62190MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.7≥ 10.12.0, < 10.12.3+1 more2025-12-17
CVE-2025-62190 [MEDIUM] CWE-352 CVE-2025-62190: Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls ve
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link
nvd
CVE-2025-62690MEDIUMCVSS 6.1≥ 10.11.0, < 10.11.52025-12-17
CVE-2025-62690 [MEDIUM] CWE-601 CVE-2025-62690: Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allo
Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.
nvd
CVE-2025-13352LOWCVSS 3.0≥ 10.11.0, < 10.11.72025-12-17
CVE-2025-13352 [LOW] CWE-1287 CVE-2025-13352: Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validat
Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
nvd
CVE-2025-13324LOWCVSS 3.7≥ 10.11.0, < 10.11.6≥ 10.12.0, < 10.12.3+1 more2025-12-17
CVE-2025-13324 [LOW] CWE-863 CVE-2025-13324: Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remo
Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actio
nvd
CVE-2025-13870MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.52025-12-02
CVE-2025-13870 [MEDIUM] CWE-306 CVE-2025-13870: Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when
Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
nvd
CVE-2025-12756MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-12-01
CVE-2025-12756 [MEDIUM] CWE-863 CVE-2025-12756: Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.
nvd
CVE-2025-12421CRITICALCVSS 9.9≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-11-27
CVE-2025-12421 [CRITICAL] CWE-303 CVE-2025-12421: Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods
nvd
CVE-2025-12419CRITICALCVSS 9.9≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-11-27
CVE-2025-12419 [CRITICAL] CWE-303 CVE-2025-12419: Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail
Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow.
nvd
CVE-2025-12559MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-11-27
CVE-2025-12559 [MEDIUM] CWE-200 CVE-2025-12559: Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
nvd
CVE-2025-55074LOWCVSS 3.5≥ 10.5.0, < 10.5.12≥ 10.11.0, < 10.11.42025-11-18
CVE-2025-55074 [LOW] CWE-1426 CVE-2025-55074: Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects
nvd
CVE-2025-55070HIGHCVSS 7.5fixed in 11.0.02025-11-14
CVE-2025-55070 [HIGH] CWE-306 CVE-2025-55070: Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which a
Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events
nvd
CVE-2025-11776MEDIUMCVSS 4.3fixed in 11.0.02025-11-14
CVE-2025-11776 [MEDIUM] CWE-863 CVE-2025-11776: Mattermost versions <11 fail to properly restrict access to archived channel search API which allows
Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint
nvd
CVE-2025-41436MEDIUMCVSS 4.3fixed in 11.0.02025-11-14
CVE-2025-41436 [MEDIUM] CWE-863 CVE-2025-41436: Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setti
Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads
nvd
CVE-2025-55073MEDIUMCVSS 5.3≥ 10.5.0, < 10.5.12≥ 10.11.0, < 10.11.4+1 more2025-11-14
CVE-2025-55073 [MEDIUM] CWE-306 CVE-2025-55073: Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the r
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL.
nvd
CVE-2025-11794MEDIUMCVSS 4.9≥ 10.5.0, < 10.5.12≥ 10.11.0, < 10.11.4+1 more2025-11-14
CVE-2025-11794 [MEDIUM] CWE-200 CVE-2025-11794: Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and MFA secrets via the POST /api/v4/users/{user_id}/email/verify/member endpoint
nvd
CVE-2025-11777MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.12≥ 10.11.0, < 10.11.42025-11-13
CVE-2025-11777 [MEDIUM] CWE-863 CVE-2025-11777: Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint
nvd