cbcvebase.

Mattermost Server vulnerabilities

445 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41

Vulnerabilities

Page 9 of 23
CVE-2025-13821P4MEDIUMCVSS 5.7≥ 10.11.0, < 10.11.10≥ 11.1.0, < 11.1.3+1 more2026-02-16
CVE-2025-13821 [MEDIUM] CWE-200 CVE-2025-13821: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitiv Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost Advisory ID: MMSA-2025-00560
nvd
CVE-2017-18916P4MEDIUMCVSS 5.3fixed in 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18916 [MEDIUM] CWE-732 CVE-2017-18916: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access con An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.
nvd
CVE-2019-20880P4HIGHCVSS 7.5fixed in 4.10.7≥ 5.6.0, < 5.6.5+2 more2020-06-19
CVE-2019-20880 [HIGH] CWE-770 CVE-2019-20880: An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attac An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.
nvd
CVE-2026-5139P4MEDIUMCVSS 5.4≥ 10.11.0, < 10.11.18≥ 11.5.0, < 11.5.6+2 more2026-06-22
CVE-2026-5139 [MEDIUM] CWE-862 CVE-2026-5139: Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail t Mattermost versions 11.7.x }} slash command.. Mattermost Advisory ID: MMSA-2026-00644
nvd
CVE-2025-3230P4MEDIUMCVSS 5.4≥ 9.11.0, < 9.11.13≥ 10.5.0, < 10.5.4+2 more2025-05-30
CVE-2025-3230 [MEDIUM] CWE-303 CVE-2025-3230: Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.
nvd
CVE-2025-46702P4MEDIUMCVSS 5.4≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-30
CVE-2025-46702 [MEDIUM] CWE-863 CVE-2025-46702: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from privat
nvd
CVE-2026-10085P4MEDIUMCVSS 5.4≥ 10.11.0, < 10.11.20≥ 11.6.0, < 11.6.5+1 more2026-07-13
CVE-2026-10085 [MEDIUM] CWE-862 CVE-2026-10085: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the gro Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID:
nvd
CVE-2026-4274P4MEDIUMCVSS 5.4≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+2 more2026-03-26
CVE-2026-4274 [MEDIUM] CWE-863 CVE-2026-4274: Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail t Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user access to an entire private team instead of only the shared channel via sending crafted membership sync messages
nvd
CVE-2025-6233P4MEDIUMCVSS 4.9≥ 9.11.0, < 9.11.17≥ 10.5.0, < 10.5.8+2 more2025-07-18
CVE-2025-6233 [MEDIUM] CWE-22 CVE-2025-6233: Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.
nvd
CVE-2022-3147P4MEDIUMCVSS 6.5fixed in 7.1.02022-09-09
CVE-2022-3147 [MEDIUM] CWE-400 CVE-2022-3147: Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.
nvd
CVE-2016-11072P4MEDIUMCVSS 6.5fixed in 3.0.22020-06-19
CVE-2016-11072 [MEDIUM] CWE-287 CVE-2016-11072: An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Sessio An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
nvd
CVE-2023-1776P4MEDIUMCVSS 5.4fixed in 7.1.6v7.7.12023-03-31
CVE-2023-1776 [MEDIUM] CWE-79 CVE-2023-1776: Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a c Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
nvd
CVE-2017-18871P4HIGHCVSS 7.5fixed in 4.2.2≥ 4.3.0, < 4.3.4+2 more2020-06-19
CVE-2017-18871 [HIGH] CVE-2017-18871: An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attack An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name.
nvd
CVE-2022-2366P4MEDIUMCVSS 5.3fixed in 6.3.9≥ 6.4.0, < 6.5.2+2 more2022-07-12
CVE-2022-2366 [MEDIUM] CWE-276 CVE-2022-2366: Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.
nvd
CVE-2025-2475P4MEDIUMCVSS 5.4≥ 9.11.0, < 9.11.10≥ 10.4.0, < 10.4.4+1 more2025-04-14
CVE-2025-2475 [MEDIUM] CWE-303 CVE-2025-2475: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cach Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
nvd
CVE-2024-11599P4MEDIUMCVSS 5.3≥ 9.5.0, < 9.5.12≥ 9.11.0, < 9.11.4+2 more2024-11-28
CVE-2024-11599 [MEDIUM] CWE-754 CVE-2024-11599: Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to pr Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration.
nvd
CVE-2025-47871P4MEDIUMCVSS 5.4≥ 9.11.0, < 9.11.16≥ 10.5.0, < 10.5.6+3 more2025-06-30
CVE-2025-47871 [MEDIUM] CWE-863 CVE-2025-47871: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel
nvd
CVE-2026-9597P4MEDIUMCVSS 5.4≥ 11.6.0, < 11.6.5≥ 11.7.0, < 11.7.32026-07-13
CVE-2026-9597 [MEDIUM] CWE-305 CVE-2026-9597: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is dea Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
nvd
CVE-2026-6333P4MEDIUMCVSS 5.0≥ 10.11.0, < 10.11.14≥ 11.5.0, < 11.5.22026-05-18
CVE-2026-6333 [MEDIUM] CWE-918 CVE-2026-6333: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when cons Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermost Advisory ID: MMSA-2026-00582
nvd
CVE-2023-7113P4MEDIUMCVSS 6.1fixed in 8.1.72023-12-29
CVE-2023-7113 [MEDIUM] CWE-79 CVE-2023-7113: Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows a Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
nvd
Mattermost Server vulnerabilities | cvebase