Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 8 of 23
CVE-2025-27936P4MEDIUMCVSS 5.9fixed in 10.5.22025-04-16
CVE-2025-27936 [MEDIUM] CWE-208 CVE-2025-27936: Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.
nvd
CVE-2024-32045P4MEDIUMCVSS 5.9≥ 8.1.0, < 8.1.13≥ 9.5.0, < 9.5.4+1 more2024-05-26
CVE-2024-32045 [MEDIUM] CWE-284 CVE-2024-32045: Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access co
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members of.
nvd
CVE-2020-14450P4HIGHCVSS 7.5fixed in 5.22.02020-06-19
CVE-2020-14450 [HIGH] CVE-2020-14450: An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers t
An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers to cause a denial of service (client-side), aka MMSA-2020-0017.
nvd
CVE-2020-14447P4HIGHCVSS 7.5fixed in 5.23.02020-06-19
CVE-2020-14447 [HIGH] CWE-835 CVE-2020-14447: An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers t
An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0021.
nvd
CVE-2024-39837P4MEDIUMCVSS 5.4≥ 9.5.0, < 9.5.7v9.9.02024-08-01
CVE-2024-39837 [MEDIUM] CWE-284 CVE-2024-39837: Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.
nvd
CVE-2020-14453P4HIGHCVSS 7.5fixed in 5.21.02020-06-19
CVE-2020-14453 [HIGH] CWE-345 CVE-2020-14453: An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropria
An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005.
nvd
CVE-2022-3257P4MEDIUMCVSS 6.5fixed in 7.2.02022-09-23
CVE-2022-3257 [MEDIUM] CWE-400 CVE-2022-3257: Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file w
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.
nvd
CVE-2016-11078P4MEDIUMCVSS 6.5fixed in 3.0.02020-06-19
CVE-2016-11078 [MEDIUM] CWE-200 CVE-2016-11078: An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.
nvd
CVE-2019-20873P4MEDIUMCVSS 6.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20873 [MEDIUM] CVE-2019-20873: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attac
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation.
nvd
CVE-2020-14460P4MEDIUMCVSS 6.5fixed in 5.9.8≥ 5.16.0, < 5.16.5+3 more2020-06-19
CVE-2020-14460 [MEDIUM] CVE-2020-14460: An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creat
An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAuth application does not always require admin privileges, aka MMSA-2020-0001.
nvd
CVE-2019-20854P4HIGHCVSS 7.5fixed in 5.17.02020-06-19
CVE-2019-20854 [HIGH] CVE-2019-20854: An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a de
An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message.
nvd
CVE-2019-20888P4HIGHCVSS 7.5fixed in 4.10.5≥ 5.5.0, < 5.5.2+2 more2020-06-19
CVE-2019-20888 [HIGH] CWE-401 CVE-2019-20888: An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attacke
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.
nvd
CVE-2020-14448P4HIGHCVSS 7.5fixed in 5.23.02020-06-19
CVE-2020-14448 [HIGH] CWE-835 CVE-2020-14448: An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow a
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0020.
nvd
CVE-2019-20845P4HIGHCVSS 7.5fixed in 5.18.02020-06-19
CVE-2019-20845 [HIGH] CWE-770 CVE-2019-20845: An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of
An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack import.
nvd
CVE-2019-20857P4HIGHCVSS 7.5fixed in 5.16.02020-06-19
CVE-2019-20857 [HIGH] CVE-2019-20857: An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of
An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown renderer hang) via many backtick characters.
nvd
CVE-2015-9548P4HIGHCVSS 7.5fixed in 1.2.02020-06-19
CVE-2015-9548 [HIGH] CWE-400 CVE-2015-9548: An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of
An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.
nvd
CVE-2024-42406P4MEDIUMCVSS 5.4≥ 9.5.0, < 9.5.9≥ 9.9.0, < 9.9.3+2 more2024-09-26
CVE-2024-42406 [MEDIUM] CWE-284 CVE-2024-42406: Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to pr
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.
nvd
CVE-2026-28735P4MEDIUMCVSS 5.4≥ 10.11.0, < 10.11.15≥ 11.4.0, < 11.4.5+2 more2026-05-22
CVE-2026-28735 [MEDIUM] CWE-863 CVE-2026-28735: Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL.. Mattermost Advisory ID: MMSA-2026-00628
nvd
CVE-2025-55073P4MEDIUMCVSS 5.3≥ 10.5.0, < 10.5.12≥ 10.11.0, < 10.11.4+1 more2025-11-14
CVE-2025-55073 [MEDIUM] CWE-306 CVE-2025-55073: Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the r
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL.
nvd
CVE-2026-3112P4MEDIUMCVSS 4.9≥ 10.11.0, < 10.11.12≥ 11.2.0, < 11.2.4+2 more2026-03-26
CVE-2026-3112 [MEDIUM] CWE-22 CVE-2026-3112: Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail t
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced Logging file target paths which allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in support packet generation. Mattermost Advisory ID: MMSA-2025-00562
nvd