Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 6 of 23
CVE-2017-18909P3HIGHCVSS 7.5fixed in 3.9.02020-06-19
CVE-2017-18909 [HIGH] CWE-295 CVE-2017-18909: An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signatur
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
nvd
CVE-2023-3593P3MEDIUMCVSS 6.5≥ 7.8.0, < 7.8.7≥ 7.9.0, < 7.9.5+1 more2023-07-17
CVE-2023-3593 [MEDIUM] CWE-400 CVE-2023-3593: Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a speci
Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.
nvd
CVE-2024-54083P3MEDIUMCVSS 6.5≥ 9.5.0, < 9.5.13≥ 9.11.0, < 9.11.5+2 more2024-12-16
CVE-2024-54083 [MEDIUM] CWE-1287 CVE-2024-54083: Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to pr
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.
nvd
CVE-2025-20088P3MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.6≥ 10.0.0, < 10.0.4+2 more2025-01-15
CVE-2025-20088 [MEDIUM] CWE-1287 CVE-2025-20088: Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to p
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
nvd
CVE-2025-21088P3MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.6≥ 10.0.0, < 10.0.4+2 more2025-01-15
CVE-2025-21088 [MEDIUM] CWE-704 CVE-2025-21088: Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to p
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
nvd
CVE-2026-3114P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.12≥ 11.2.0, < 11.2.4+2 more2026-03-26
CVE-2026-3114 [MEDIUM] CWE-409 CVE-2026-3114: Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail t
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highly compressed entries (zip bombs) that exhaust server m
nvd
CVE-2026-26233P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.12≥ 11.2.0, < 11.2.4+2 more2026-03-25
CVE-2026-26233 [MEDIUM] CWE-400 CVE-2026-26233: Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail t
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login requests which allows unauthenticated remote attackers to cause denial of service (server crash and restart) via HTTP/2 single packet attack with 100+ parallel login requests.. Mattermost Advisory ID: MMSA-2025-00566
nvd
CVE-2026-6850P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.20≥ 11.6.0, < 11.6.5+1 more2026-07-13
CVE-2026-6850 [MEDIUM] CWE-1333 CVE-2026-6850: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the len
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-s
nvd
CVE-2026-6340P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-18
CVE-2026-6340 [MEDIUM] CWE-789 CVE-2026-6340: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip ar
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted 7zip file with excessive folder declarations.. Mattermost Advisory ID: MMSA-2026-00573
nvd
CVE-2024-2447P3MEDIUMCVSS 6.5≥ 8.1.0, < 8.1.11≥ 9.3.0, < 9.3.3+2 more2024-04-05
CVE-2024-2447 [MEDIUM] CWE-284 CVE-2024-2447: Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.
nvd
CVE-2024-31859P3MEDIUMCVSS 6.3≥ 8.1.0, < 8.1.13≥ 9.5.0, < 9.5.4+1 more2024-05-26
CVE-2024-31859 [MEDIUM] CWE-284 CVE-2024-31859: Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper author
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin
nvd
CVE-2025-41410P3MEDIUMCVSS 5.4≥ 10.5.0, < 10.5.11≥ 10.10.0, < 10.10.3+1 more2025-10-16
CVE-2025-41410 [MEDIUM] CWE-862 CVE-2025-41410: Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email
Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verified user accounts with arbitrary email domains via malicious Slack import data to bypass email-based team access restrictions
nvd
CVE-2017-18917P4HIGHCVSS 7.5≥ 3.6.0, < 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18917 [HIGH] CWE-916 CVE-2017-18917: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used f
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.
nvd
CVE-2019-20881P3HIGHCVSS 7.3fixed in 5.8.02020-06-19
CVE-2019-20881 [HIGH] CWE-307 CVE-2019-20881: An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
nvd
CVE-2025-20033P4MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.6≥ 10.0.0, < 10.0.4+2 more2025-01-09
CVE-2025-20033 [MEDIUM] CWE-1287 CVE-2025-20033: Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly va
Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_notification type and specific props.
nvd
CVE-2024-22091P4MEDIUMCVSS 6.5≥ 8.1.0, < 8.1.12≥ 9.5.0, < 9.5.3+1 more2024-04-26
CVE-2024-22091 [MEDIUM] CWE-400 CVE-2024-22091: Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limi
Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths
nvd
CVE-2025-20086P3MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.6≥ 10.0.0, < 10.0.4+2 more2025-01-15
CVE-2025-20086 [MEDIUM] CWE-1287 CVE-2025-20086: Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to p
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
nvd
CVE-2026-21388P4MEDIUMCVSS 6.5≤ 2.3.12026-04-09
CVE-2026-21388 [MEDIUM] CWE-770 CVE-2026-21388: Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the webhoo
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610
nvd
CVE-2026-4915P4MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-25
CVE-2026-4915 [MEDIUM] CWE-754 CVE-2026-4915: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attachment payloads before processing, which allows an authenticated user to cause a denial of service (server process termination) via a crafted webhook callback response containing a null attachment entry..
nvd
CVE-2026-5755P3MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-22
CVE-2026-5755 [MEDIUM] CWE-400 CVE-2026-5755: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset in the image header before allocating memory, which allows authenticated users with file upload or posting permissions to cause a denial of service (server OOM) via uploading a crafted TIFF file or posting
nvd