cbcvebase.

Mattermost Server vulnerabilities

445 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41

Vulnerabilities

Page 4 of 23
CVE-2025-31363P3MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.3+1 more2025-04-16
CVE-2025-31363 [MEDIUM] CWE-1426 CVE-2025-31363: Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains th Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt injection in the AI plugin's Jira tool.
nvd
CVE-2019-20865P3HIGHCVSS 8.8fixed in 4.10.10≥ 5.9.0, < 5.9.2+3 more2020-06-19
CVE-2019-20865 [HIGH] CWE-352 CVE-2019-20865: An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.
nvd
CVE-2017-18894P3HIGHCVSS 8.1fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18894 [HIGH] CWE-732 CVE-2017-18894: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
nvd
CVE-2023-3591P3HIGHCVSS 8.2≥ 7.8.0, < 7.8.7≥ 7.9.0, < 7.9.5+1 more2023-07-17
CVE-2023-3591 [HIGH] CWE-287 CVE-2023-3591: Mattermost fails to invalidate previously generated password reset tokens when a new reset token was Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
nvd
CVE-2020-14458P3HIGHCVSS 7.5fixed in 5.19.02020-06-19
CVE-2020-14458 [HIGH] CVE-2020-14458: An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-0004.
nvd
CVE-2022-0903P3HIGHCVSS 7.5fixed in 5.37.8≥ 6.0.0, < 6.1.3+2 more2022-03-10
CVE-2022-0903 [HIGH] CWE-787 CVE-2022-0903: A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and inclu A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
nvd
CVE-2023-49607P3HIGHCVSS 7.5≤ 7.8.14≥ 8.0.0, ≤ 8.1.5+4 more2023-12-12
CVE-2023-49607 [HIGH] CWE-754 CVE-2023-49607: Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playbook Plugin when updating the status dialog.
nvd
CVE-2025-20621P3HIGHCVSS 7.5≥ 9.11.0, < 9.11.6≥ 10.0.0, < 10.0.4+2 more2025-01-16
CVE-2025-20621 [HIGH] CWE-1287 CVE-2025-20621: Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to p Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel.
nvd
CVE-2024-47401P3HIGHCVSS 7.5≥ 9.5.0, < 9.5.10≥ 9.10.0, < 9.10.3+1 more2024-10-29
CVE-2024-47401 [HIGH] CWE-770 CVE-2024-47401: Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed e Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks.
nvd
CVE-2025-9081P3MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.17≥ 10.5.0, < 10.5.92025-09-19
CVE-2025-9081 [MEDIUM] CWE-639 CVE-2025-9081: Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls wh Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration
nvd
CVE-2025-9076P3MEDIUMCVSS 6.5≥ 10.10.0, < 10.10.22025-09-15
CVE-2025-9076 [MEDIUM] CWE-862 CVE-2025-9076: Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel mem Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.
nvd
CVE-2026-5163P3MEDIUMCVSS 6.5≥ 11.5.0, < 11.5.22026-05-18
CVE-2026-5163 [MEDIUM] CWE-862 CVE-2026-5163: Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted m Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of threads in private channels and direct messages they do not have access to via a crafted request to the post rewrite endpoint.. Mattermost Advisory ID: MMSA-2026-00645
nvd
CVE-2019-20841P3HIGHCVSS 8.8fixed in 5.9.7≥ 5.15.0, < 5.15.4+3 more2020-06-19
CVE-2019-20841 [HIGH] CWE-352 CVE-2019-20841: An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.
nvd
CVE-2019-20862P3HIGHCVSS 7.5fixed in 5.13.02020-06-19
CVE-2019-20862 [HIGH] CVE-2019-20862: An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash com An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands.
nvd
CVE-2019-20886P3HIGHCVSS 7.5fixed in 5.8.02020-06-19
CVE-2019-20886 [HIGH] CWE-269 CVE-2019-20886: An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.
nvd
CVE-2025-41395P3HIGHCVSS 7.5≥ 9.11.0, < 9.11.11≥ 10.4.0, < 10.4.3+1 more2025-04-24
CVE-2025-41395 [HIGH] CWE-1287 CVE-2025-41395: Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.
nvd
CVE-2025-20051P3MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.8≥ 10.2.0, < 10.2.3+2 more2025-02-24
CVE-2025-20051 [MEDIUM] CWE-22 CVE-2025-20051: Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to p Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially crafted block in Boards.
nvd
CVE-2026-6345P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-6345 [MEDIUM] CWE-522 CVE-2026-6345: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate a user via the use of some of those passwords.. Mattermost Advisory ID: MMSA-2026-00614
nvd
CVE-2026-3117P3MEDIUMCVSS 6.5≥ 10.13.0, ≤ 10.13.11≥ 11.1.0, ≤ 11.1.5+1 more2026-05-18
CVE-2026-3117 [MEDIUM] CWE-862 CVE-2026-3117: Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions w Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab instance {option}}} or the {{/gitlab webhook {option}}} commands. Mattermost Advisory ID: MMSA-2026-00600
nvd
CVE-2026-10106P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.20≥ 11.6.0, < 11.6.5+1 more2026-07-13
CVE-2026-10106 [MEDIUM] CWE-863 CVE-2026-10106: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible
nvd
Mattermost Server vulnerabilities | cvebase