Mattermost Server vulnerabilities
417 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
417
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH77MEDIUM288LOW36
Vulnerabilities
Page 6 of 21
CVE-2025-49810MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.92025-08-21
CVE-2025-49810 [MEDIUM] CWE-863 CVE-2025-49810: Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows
Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts
nvd
CVE-2025-47870MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+2 more2025-08-21
CVE-2025-47870 [MEDIUM] CWE-306 CVE-2025-47870: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.
nvd
CVE-2025-49222MEDIUMCVSS 6.8≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+3 more2025-08-21
CVE-2025-49222 [MEDIUM] CWE-434 CVE-2025-49222: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster upload sessions which allows a system admin to upload non-attachment file types via shared channels that could potentially be placed in arbitrary filesystem directories.
nvd
CVE-2025-8023MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+2 more2025-08-21
CVE-2025-8023 [MEDIUM] CWE-22 CVE-2025-8023: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, which allows a system admin to perform path traversal attacks via malicious path components, potentially enabling malicious file placement outside intended directories.
nvd
CVE-2025-8402MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+3 more2025-08-21
CVE-2025-8402 [MEDIUM] CWE-476 CVE-2025-8402: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.
nvd
CVE-2025-6465MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.9≥ 10.8.0, < 10.8.4+2 more2025-08-21
CVE-2025-6465 [MEDIUM] CWE-22 CVE-2025-6465: Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.
nvd
CVE-2025-36530MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.9+2 more2025-08-21
CVE-2025-36530 [MEDIUM] CWE-22 CVE-2025-36530: Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to
Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.
nvd
CVE-2025-53971LOWCVSS 3.8≥ 9.11.0, < 9.11.18≥ 10.5.0, < 10.5.92025-08-21
CVE-2025-53971 [LOW] CWE-863 CVE-2025-53971: Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint.
nvd
CVE-2025-47700LOWCVSS 3.5≥ 10.5.0, < 10.5.92025-08-21
CVE-2025-47700 [LOW] CWE-918 CVE-2025-47700: Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request
Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions
nvd
CVE-2025-6233MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.17≥ 10.5.0, < 10.5.8+2 more2025-07-18
CVE-2025-6233 [MEDIUM] CWE-22 CVE-2025-6233: Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to
Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.
nvd
CVE-2025-6226MEDIUMCVSS 6.5≥ 9.11.0, < 9.11.17≥ 10.5.0, < 10.5.7+2 more2025-07-18
CVE-2025-6226 [MEDIUM] CWE-306 CVE-2025-6226: Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to
Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts.
nvd
CVE-2025-6227LOWCVSS 3.1≥ 9.11.0, < 9.11.17≥ 10.5.0, < 10.5.82025-07-18
CVE-2025-6227 [LOW] CWE-522 CVE-2025-6227: Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting
Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.
nvd
CVE-2025-47871MEDIUMCVSS 5.4≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-30
CVE-2025-47871 [MEDIUM] CWE-863 CVE-2025-47871: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel
nvd
CVE-2025-46702MEDIUMCVSS 5.4≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-30
CVE-2025-46702 [MEDIUM] CWE-863 CVE-2025-46702: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from privat
nvd
CVE-2025-4981CRITICALCVSS 9.9≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-20
CVE-2025-4981 [CRITICAL] CWE-427 CVE-2025-4981: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code
nvd
CVE-2025-3228MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-20
CVE-2025-3228 [MEDIUM] CWE-863 CVE-2025-3228: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run.
nvd
CVE-2025-3227MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-20
CVE-2025-3227 [MEDIUM] CWE-863 CVE-2025-3227: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run p
nvd
CVE-2025-4128MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.14≥ 10.5.0, < 10.5.52025-06-11
CVE-2025-4128 [MEDIUM] CWE-863 CVE-2025-4128: Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team
Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
nvd
CVE-2025-4573MEDIUMCVSS 4.1≥ 9.11.0, < 9.11.14≥ 10.5.0, < 10.5.5+2 more2025-06-11
CVE-2025-4573 [MEDIUM] CWE-90 CVE-2025-4573: Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to
Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT /api/v4/ldap/groups/{remote_id}/link API when objectGUID
nvd
CVE-2025-3230MEDIUMCVSS 5.4≥ 9.11.0, < 9.11.13≥ 10.5.0, < 10.5.4+2 more2025-05-30
CVE-2025-3230 [MEDIUM] CWE-303 CVE-2025-3230: Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.
nvd