cbcvebase.

Mattermost Server vulnerabilities

445 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41

Vulnerabilities

Page 3 of 23
CVE-2018-21251P3CRITICALCVSS 9.8fixed in 5.1.1v5.2.02020-06-19
CVE-2018-21251 [CRITICAL] CWE-862 CVE-2018-21251: An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed i An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.
nvd
CVE-2023-3590P3HIGHCVSS 7.5≥ 7.10.0, < 7.10.32023-07-17
CVE-2023-3590 [HIGH] CWE-863 CVE-2023-3590: Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attach Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.
nvd
CVE-2026-20719P3HIGHCVSS 7.5≥ 10.11.0, < 10.11.12≥ 11.2.0, < 11.2.4+2 more2026-03-25
CVE-2026-20719 [HIGH] CWE-754 CVE-2026-20719: Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail t Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595
nvd
CVE-2026-24458P3HIGHCVSS 7.5≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-24458 [HIGH] CWE-770 CVE-2026-24458: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Mattermost Advisory ID: MMSA-2026-00587
nvd
CVE-2025-24490P3MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.8≥ 10.2.0, < 10.2.3+2 more2025-02-24
CVE-2025-24490 [MEDIUM] CWE-89 CVE-2025-24490: Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to u Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reordering specially crafted boards categories.
nvd
CVE-2017-18906P3HIGHCVSS 8.1fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18906 [HIGH] CWE-287 CVE-2017-18906: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OA An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
nvd
CVE-2018-21264P3HIGHCVSS 8.8fixed in 4.5.2≥ 4.6.0, < 4.6.2+1 more2020-06-19
CVE-2018-21264 [HIGH] CWE-20 CVE-2018-21264: An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.
nvd
CVE-2017-18884P3HIGHCVSS 8.1fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18884 [HIGH] CWE-269 CVE-2017-18884: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
nvd
CVE-2023-5330P3HIGHCVSS 7.5fixed in 7.8.11≥ 8.0.0, < 8.0.3+1 more2023-10-09
CVE-2023-5330 [HIGH] CWE-400 CVE-2023-5330: Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.
nvd
CVE-2026-5308P3HIGHCVSS 7.5≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-22
CVE-2026-5308 [HIGH] CWE-400 CVE-2026-5308: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a denial of service via crafted oversized HTTP requests.. Mattermost Advisory ID: MMSA-2026-00646
nvd
CVE-2026-2462P3MEDIUMCVSS 6.6≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-2462 [MEDIUM] CWE-863 CVE-2026-2462: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin aft
nvd
CVE-2026-6062P3MEDIUMCVSS 6.4≥ 10.11.0, < 10.11.18≥ 11.5.0, < 11.5.6+2 more2026-06-22
CVE-2026-6062 [MEDIUM] CWE-639 CVE-2026-6062: Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail t Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subscription before applying edits which allows an authenticated attacker to hijack subscriptions from channels they have no access to via a crafted PUT request to the subscription edit endpoint.. Mattermost A
nvd
CVE-2023-4478P3HIGHCVSS 8.2fixed in 7.8.9≥ 7.9.0, < 7.10.5+1 more2023-08-25
CVE-2023-4478 [HIGH] CWE-74 CVE-2023-4478: Mattermost fails to restrict which parameters' values it takes from the request during signup allowi Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.
nvd
CVE-2016-11066P3HIGHCVSS 7.5fixed in 3.2.02020-06-19
CVE-2016-11066 [HIGH] CWE-200 CVE-2016-11066: An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessar An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
nvd
CVE-2019-20885P3HIGHCVSS 7.5fixed in 5.8.02020-06-19
CVE-2019-20885 [HIGH] CWE-862 CVE-2019-20885: An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
nvd
CVE-2023-45847P3HIGHCVSS 7.5≤ 7.8.14≥ 8.0.0, ≤ 8.1.5+3 more2023-12-12
CVE-2023-45847 [HIGH] CWE-400 CVE-2023-45847: Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allo Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to send a specially crafted request and crash the Playbooks plugin
nvd
CVE-2023-1831P3HIGHCVSS 7.5fixed in 7.7.3≥ 7.8.0, < 7.8.2+1 more2023-04-17
CVE-2023-1831 [HIGH] CWE-200 CVE-2023-1831: Mattermost fails to redact from audit logs the user password during user creation and the user passw Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).
nvd
CVE-2025-35965P3HIGHCVSS 7.5≥ 9.11.0, < 9.11.11≥ 10.4.0, < 10.4.3+1 more2025-04-24
CVE-2025-35965 [HIGH] CWE-770 CVE-2025-35965: Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqu Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-
nvd
CVE-2019-20842P3HIGHCVSS 7.2fixed in 5.9.7≥ 5.15.0, < 5.15.4+3 more2020-06-19
CVE-2019-20842 [HIGH] CWE-89 CVE-2019-20842: An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by admins via SearchAllChannels.
nvd
CVE-2024-41144P3HIGHCVSS 7.1≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-41144 [HIGH] CWE-284 CVE-2024-41144: Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled, which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels
nvd
Mattermost Server vulnerabilities | cvebase