Mattermost Server vulnerabilities

389 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
389
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH74MEDIUM266LOW34

Vulnerabilities

Page 6 of 20
CVE-2025-41395HIGHCVSS 7.5≥ 9.11.0, < 9.11.11≥ 10.4.0, < 10.4.3+1 more2025-04-24
CVE-2025-41395 [HIGH] CWE-1287 CVE-2025-41395: Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.
nvd
CVE-2025-35965HIGHCVSS 7.5≥ 9.11.0, < 9.11.11≥ 10.4.0, < 10.4.3+1 more2025-04-24
CVE-2025-35965 [HIGH] CWE-770 CVE-2025-35965: Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqu Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-
nvd
CVE-2025-41423MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.11≥ 10.4.0, < 10.4.3+1 more2025-04-24
CVE-2025-41423 [MEDIUM] CWE-863 CVE-2025-41423: Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.
nvd
CVE-2025-24839MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-16
CVE-2025-24839 [MEDIUM] CWE-863 CVE-2025-24839: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler po Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override property to a post via the Wrangler plugin, provided both the AI and Wrangler plugins are enabled.
nvd
CVE-2025-27571MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-16
CVE-2025-27571 [MEDIUM] CWE-863 CVE-2025-27571: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Us Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived Channels" configuration when fetching channel metadata of a post from archived channels, which allows authenticated users to access such information when a channel is archived.
nvd
CVE-2025-27936MEDIUMCVSS 5.9fixed in 10.5.22025-04-16
CVE-2025-27936 [MEDIUM] CWE-208 CVE-2025-27936: Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.
nvd
CVE-2025-31363MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.3+1 more2025-04-16
CVE-2025-31363 [MEDIUM] CWE-1426 CVE-2025-31363: Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains th Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt injection in the AI plugin's Jira tool.
nvd
CVE-2025-2564MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-16
CVE-2025-2564 [MEDIUM] CWE-863 CVE-2025-2564: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce th Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.
nvd
CVE-2025-27538LOWCVSS 2.7≥ 9.11.0, < 9.11.10≥ 10.5.0, < 10.5.22025-04-16
CVE-2025-27538 [LOW] CWE-306 CVE-2025-27538: Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/use Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if those users have not set up MFA.
nvd
CVE-2025-32093MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-14
CVE-2025-32093 [MEDIUM] CWE-863 CVE-2025-32093: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain op Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system administrators via improper permission validation.
nvd
CVE-2025-2475MEDIUMCVSS 5.4≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-14
CVE-2025-2475 [MEDIUM] CWE-303 CVE-2025-2475: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cach Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
nvd
CVE-2025-2424MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.10≥ 10.5.0, < 10.5.22025-04-14
CVE-2025-2424 [MEDIUM] CWE-863 CVE-2025-2424: Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
nvd
CVE-2025-24866LOWCVSS 2.7≥ 9.11.0, < 9.11.92025-04-10
CVE-2025-24866 [LOW] CWE-863 CVE-2025-24866: Mattermost versions 9.11.x <= 9.11.8  fail to enforce proper access controls on the /api/v4/audits e Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
nvd
CVE-2025-25068HIGHCVSS 8.8≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+2 more2025-03-21
CVE-2025-25068 [HIGH] CWE-306 CVE-2025-25068: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to e Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.
nvd
CVE-2025-25274HIGHCVSS 8.8≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+1 more2025-03-21
CVE-2025-25274 [HIGH] CWE-863 CVE-2025-25274: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command ex Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.
nvd
CVE-2025-30179MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+1 more2025-03-21
CVE-2025-30179 [MEDIUM] CWE-863 CVE-2025-30179: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on cert Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries.
nvd
CVE-2025-27933MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+1 more2025-03-21
CVE-2025-27933 [MEDIUM] CWE-863 CVE-2025-27933: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce cha Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public
nvd
CVE-2025-24920MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+2 more2025-03-21
CVE-2025-24920 [MEDIUM] CWE-863 CVE-2025-24920: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to r Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels
nvd
CVE-2025-27715LOWCVSS 2.7≥ 9.11.0, < 9.11.92025-03-21
CVE-2025-27715 [LOW] CWE-863 CVE-2025-27715: Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.
nvd
CVE-2025-1472MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.92025-03-19
CVE-2025-1472 [MEDIUM] CWE-863 CVE-2025-1472: Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
nvd