cbcvebase.

Mattermost Server vulnerabilities

417 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
417
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH77MEDIUM288LOW36

Vulnerabilities

Page 4 of 21
CVE-2026-0997MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.10≥ 11.1.0, < 11.1.3+1 more2026-02-16
CVE-2026-0997 [MEDIUM] CWE-863 CVE-2026-0997: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoo Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via crafted API requests.. Mattermost Adv
nvd
CVE-2026-0998MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.10≥ 11.1.0, < 11.1.3+1 more2026-02-16
CVE-2026-0998 [MEDIUM] CWE-862 CVE-2026-0998: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoo Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom meetings as any user and overwrite arbitrary posts via direct API calls with manipulated user IDs and
nvd
CVE-2025-13821MEDIUMCVSS 5.7≥ 10.11.0, < 10.11.10≥ 11.1.0, < 11.1.3+1 more2026-02-16
CVE-2025-13821 [MEDIUM] CWE-200 CVE-2025-13821: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitiv Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost Advisory ID: MMSA-2025-00560
nvd
CVE-2025-14573LOWCVSS 2.7≥ 10.11.0, < 10.11.102026-02-16
CVE-2025-14573 [LOW] CWE-862 CVE-2025-14573: Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team setting Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561
nvd
CVE-2026-22892MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.10≥ 11.0.0, < 11.1.3+1 more2026-02-13
CVE-2026-22892 [MEDIUM] CWE-863 CVE-2026-22892: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user per Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providi
nvd
CVE-2026-20796LOWCVSS 3.1≥ 10.11.0, < 10.11.102026-02-13
CVE-2026-20796 [LOW] CWE-367 CVE-2026-20796: Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of d Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549
nvd
CVE-2025-14822MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.92026-01-16
CVE-2025-14822 [MEDIUM] CWE-407 CVE-2025-14822: Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens
nvd
CVE-2025-14435MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.9≥ 11.0.0, < 11.0.7+1 more2026-01-16
CVE-2025-14435 [MEDIUM] CWE-770 CVE-2025-14435: Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.
nvd
CVE-2025-13767MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.8≥ 10.12.0, < 10.12.4+2 more2025-12-24
CVE-2025-13767 [MEDIUM] CWE-863 CVE-2025-13767: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
nvd
CVE-2025-64641MEDIUMCVSS 4.1≥ 10.11.0, < 10.11.8≥ 10.12.0, < 10.12.4+2 more2025-12-24
CVE-2025-64641 [MEDIUM] CWE-863 CVE-2025-64641: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts
nvd
CVE-2025-14273HIGHCVSS 8.3≥ 10.11.0, < 10.11.8≥ 10.12.0, < 10.12.4+2 more2025-12-22
CVE-2025-14273 [HIGH] CWE-303 CVE-2025-14273: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST
nvd
CVE-2025-12689MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.7≥ 10.12.0, < 10.12.3+1 more2025-12-17
CVE-2025-12689 [MEDIUM] CWE-1287 CVE-2025-12689: Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.
nvd
CVE-2025-62190MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.7≥ 10.12.0, < 10.12.3+1 more2025-12-17
CVE-2025-62190 [MEDIUM] CWE-352 CVE-2025-62190: Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls ve Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link
nvd
CVE-2025-62690MEDIUMCVSS 6.1≥ 10.11.0, < 10.11.52025-12-17
CVE-2025-62690 [MEDIUM] CWE-601 CVE-2025-62690: Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allo Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.
nvd
CVE-2025-13352LOWCVSS 3.0≥ 10.11.0, < 10.11.72025-12-17
CVE-2025-13352 [LOW] CWE-1287 CVE-2025-13352: Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validat Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
nvd
CVE-2025-13324LOWCVSS 3.7≥ 10.11.0, < 10.11.6≥ 10.12.0, < 10.12.3+1 more2025-12-17
CVE-2025-13324 [LOW] CWE-863 CVE-2025-13324: Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remo Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actio
nvd
CVE-2025-13870MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.52025-12-02
CVE-2025-13870 [MEDIUM] CWE-306 CVE-2025-13870: Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
nvd
CVE-2025-12756MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-12-01
CVE-2025-12756 [MEDIUM] CWE-863 CVE-2025-12756: Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.
nvd
CVE-2025-12421CRITICALCVSS 9.9≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-11-27
CVE-2025-12421 [CRITICAL] CWE-303 CVE-2025-12421: Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods
nvd
CVE-2025-12419CRITICALCVSS 9.9≥ 10.5.0, < 10.5.13≥ 10.11.0, < 10.11.5+2 more2025-11-27
CVE-2025-12419 [CRITICAL] CWE-303 CVE-2025-12419: Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow.
nvd