Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 5 of 23
CVE-2026-9571P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.20≥ 11.6.0, < 11.6.5+1 more2026-07-13
CVE-2026-9571 [MEDIUM] CWE-305 CVE-2026-9571: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-0
nvd
CVE-2026-6673P3MEDIUMCVSS 6.4≥ 10.11.0, < 10.11.18≥ 11.5.0, < 11.5.6+2 more2026-06-22
CVE-2026-6673 [MEDIUM] CWE-306 CVE-2026-6673: Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail t
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret and disrupt the Jira integration via POST to /ac/installed during the pending-install window.. Mattermost Advisory ID: MMSA-2
nvd
CVE-2019-20874P3HIGHCVSS 7.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20874 [HIGH] CVE-2019-20874: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attac
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.
nvd
CVE-2019-20855P3HIGHCVSS 7.5fixed in 5.9.6≥ 5.14.0, < 5.14.5+2 more2020-06-19
CVE-2019-20855 [HIGH] CVE-2019-20855: An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows att
An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration.
nvd
CVE-2019-20843P3HIGHCVSS 7.5fixed in 5.9.7≥ 5.15.0, < 5.15.4+3 more2020-06-19
CVE-2019-20843 [HIGH] CWE-281 CVE-2019-20843: An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.
nvd
CVE-2019-20863P3HIGHCVSS 7.5fixed in 5.13.02020-06-19
CVE-2019-20863 [HIGH] CVE-2019-20863: An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properl
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted.
nvd
CVE-2025-49222P3MEDIUMCVSS 6.8≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+3 more2025-08-21
CVE-2025-49222 [MEDIUM] CWE-434 CVE-2025-49222: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster upload sessions which allows a system admin to upload non-attachment file types via shared channels that could potentially be placed in arbitrary filesystem directories.
nvd
CVE-2025-6226P3MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.17≥ 10.5.0, < 10.5.7+2 more2025-07-18
CVE-2025-6226 [MEDIUM] CWE-306 CVE-2025-6226: Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to
Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts.
nvd
CVE-2026-2325P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-2325 [MEDIUM] CWE-770 CVE-2026-2325: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size o
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cause resource exhaustion or denial of service via a crafted oversized HTTP POST request to {{/api/v1/meetings}}.. Mattermost Advisory ID: MMSA-2026-00608
nvd
CVE-2017-18903P3HIGHCVSS 8.8fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18903 [HIGH] CWE-352 CVE-2017-18903: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
nvd
CVE-2019-20871P3HIGHCVSS 7.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20871 [HIGH] CVE-2019-20871: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown li
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking.
nvd
CVE-2024-4183P3MEDIUMCVSS 6.5≥ 8.1.0, < 8.1.12≥ 9.4.0, < 9.4.5+2 more2024-04-26
CVE-2024-4183 [MEDIUM] CWE-400 CVE-2024-4183: Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
nvd
CVE-2025-14822P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.92026-01-16
CVE-2025-14822 [MEDIUM] CWE-407 CVE-2025-14822: Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which
Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens
nvd
CVE-2025-30179P3MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+1 more2025-03-21
CVE-2025-30179 [MEDIUM] CWE-863 CVE-2025-30179: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on cert
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries.
nvd
CVE-2025-14435P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.9≥ 11.0.0, < 11.0.7+1 more2026-01-16
CVE-2025-14435 [MEDIUM] CWE-770 CVE-2025-14435: Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite
Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.
nvd
CVE-2025-12689P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.7≥ 10.12.0, < 10.12.3+1 more2025-12-17
CVE-2025-12689 [MEDIUM] CWE-1287 CVE-2025-12689: Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.
nvd
CVE-2026-3590P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.13≥ 11.3.0, < 11.3.3+2 more2026-04-15
CVE-2026-3590 [MEDIUM] CWE-367 CVE-2026-3590: Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail t
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent requests.. Mattermost Advisory ID: MMSA-2026-00624
nvd
CVE-2019-20846P3HIGHCVSS 7.5fixed in 5.18.02020-06-19
CVE-2019-20846 [HIGH] CWE-281 CVE-2019-20846: An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local
An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.
nvd
CVE-2020-14459P3HIGHCVSS 7.5fixed in 5.19.02020-06-19
CVE-2020-14459 [HIGH] CWE-20 CVE-2020-14459: An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause
An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020-0002.
nvd
CVE-2016-11069P3HIGHCVSS 7.5fixed in 3.2.02020-06-19
CVE-2016-11069 [HIGH] CWE-521 CVE-2016-11069: An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at pas
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
nvd