Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 7 of 23
CVE-2026-4054P4MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.14≥ 11.4.0, < 11.4.4+1 more2026-05-15
CVE-2026-4054 [MEDIUM] CWE-754 CVE-2026-4054: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the res
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG file served from an attacker-controlled origin under a non-SVG Content-Type header (e.g. image/png) embedded in an og:image meta tag or Markdown image link.
nvd
CVE-2019-20868P4HIGHCVSS 7.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20868 [HIGH] CWE-20 CVE-2019-20868: An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
nvd
CVE-2022-0904P4MEDIUMCVSS 6.5≥ 5.0.0, < 5.37.8≥ 6.0.0, < 6.1.3+2 more2022-03-10
CVE-2022-0904 [MEDIUM] CWE-787 CVE-2022-0904: A stack overflow bug in the document extractor in Mattermost Server in versions up to and including
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.
nvd
CVE-2022-1337P4MEDIUMCVSS 6.5≥ 5.37.0, < 5.37.9≥ 6.2.0, < 6.2.5+2 more2022-04-13
CVE-2022-1337 [MEDIUM] CWE-400 CVE-2022-1337: The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copi
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
nvd
CVE-2022-1982P4MEDIUMCVSS 6.5≥ 5.0.0, < 6.3.8≥ 6.4.0, < 6.4.3+2 more2022-06-02
CVE-2022-1982 [MEDIUM] CWE-400 CVE-2022-1982: Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated at
Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.
nvd
CVE-2024-24988P4MEDIUMCVSS 6.5fixed in 8.1.8≥ 9.0.0, < 9.1.5+1 more2024-02-29
CVE-2024-24988 [MEDIUM] CWE-400 CVE-2024-24988: Mattermost fails to properly validate the length of the emoji value in the custom user status, allow
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
nvd
CVE-2024-47003P4MEDIUMCVSS 6.5≥ 9.5.0, < 9.5.9v9.11.02024-09-26
CVE-2024-47003 [MEDIUM] CWE-400 CVE-2024-47003: Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the per
Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a permalink post and crash the frontend.
nvd
CVE-2023-1775P4MEDIUMCVSS 6.5fixed in 7.1.6v7.7.12023-03-31
CVE-2023-1775 [MEDIUM] CWE-200 CVE-2023-1775: When running in a High Availability configuration, Mattermost fails to sanitize some of the user_upd
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
nvd
CVE-2024-28053P4MEDIUMCVSS 6.5≥ 8.1.0, < 8.1.102024-03-15
CVE-2024-28053 [MEDIUM] CWE-400 CVE-2024-28053: Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.
nvd
CVE-2023-5333P4MEDIUMCVSS 6.5fixed in 7.8.11≥ 8.0.0, < 8.0.3+1 more2023-10-09
CVE-2023-5333 [MEDIUM] CWE-400 CVE-2023-5333: Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
nvd
CVE-2024-23493P4MEDIUMCVSS 6.5fixed in 8.1.9≥ 9.0.0, < 9.2.5+2 more2024-02-29
CVE-2024-23493 [MEDIUM] CWE-200 CVE-2024-23493: Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowin
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.
nvd
CVE-2026-4339P4MEDIUMCVSS 6.5≥ 10.11.0, < 10.11.19≥ 11.5.0, < 11.5.7+1 more2026-06-26
CVE-2026-4339 [MEDIUM] CWE-918 CVE-2026-4339: Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachm
Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate data from internal network servic
nvd
CVE-2026-27656P4MEDIUMCVSS 6.1≥ 10.11.0, < 10.11.12≥ 11.2.0, < 11.2.4+2 more2026-03-25
CVE-2026-27656 [MEDIUM] CWE-303 CVE-2026-27656: Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail t
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA
nvd
CVE-2024-36255P4MEDIUMCVSS 5.7≥ 8.1.0, < 8.1.13≥ 9.5.0, < 9.5.4+1 more2024-05-26
CVE-2024-36255 [MEDIUM] CWE-352 CVE-2024-36255: Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash command in some arbitrary channel.
nvd
CVE-2018-21258P4HIGHCVSS 7.5fixed in 5.1.02020-06-19
CVE-2018-21258 [HIGH] CWE-74 CVE-2018-21258: An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of se
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.
nvd
CVE-2019-20858P4HIGHCVSS 7.5fixed in 5.15.02020-06-19
CVE-2019-20858 [HIGH] CWE-400 CVE-2019-20858: An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of
An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint.
nvd
CVE-2017-18874P4MEDIUMCVSS 6.5fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18874 [MEDIUM] CWE-22 CVE-2017-18874: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for f
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
nvd
CVE-2022-2401P4MEDIUMCVSS 6.5fixed in 6.3.9≥ 6.4.0, < 6.5.2+3 more2022-07-14
CVE-2022-2401 [MEDIUM] CWE-200 CVE-2022-2401: Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.
nvd
CVE-2023-49809P4MEDIUMCVSS 6.5≤ 8.1.5≥ 9.0.0, ≤ 9.1.02023-12-12
CVE-2023-49809 [MEDIUM] CWE-400 CVE-2023-49809: Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to sen
Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoint and make it crash. After a few repetitions, the plugin is disabled.
nvd
CVE-2024-28949P4MEDIUMCVSS 6.5≥ 8.1.0, < 8.1.11≥ 9.3.0, < 9.3.3+2 more2024-04-05
CVE-2024-28949 [MEDIUM] CWE-400 CVE-2024-28949: Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
nvd