Mattermost
by Mattermost
Source repositories
CVEs (566)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-11082 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link. | ||
| CVE-2016-11079 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL. | ||
| CVE-2016-11073 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting. | ||
| CVE-2016-11071 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place. | ||
| CVE-2016-11063 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview. | ||
| CVE-2017-18904 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file. | ||
| CVE-2017-18897 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection. | ||
| CVE-2017-18893 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS. | ||
| CVE-2017-18892 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized. | ||
| CVE-2026-3116 | Med | 0.32 | 4.9 | 0.00 | Mar 26, 2026 | Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589 | ||
| CVE-2023-5193 | Med | 0.32 | 4.9 | 0.00 | Sep 29, 2023 | Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation. | ||
| CVE-2026-3473 | Med | 0.31 | 5.9 | 0.00 | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests… | ||
| CVE-2026-2454 | Med | 0.31 | 5.8 | 0.00 | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin.… | ||
| CVE-2025-31947 | Med | 0.31 | 5.8 | 0.00 | May 15, 2025 | Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost. | ||
| CVE-2024-8071 | Med | 0.31 | 4.7 | 0.00 | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to… | ||
| CVE-2023-5339 | Med | 0.31 | 4.7 | 0.00 | Oct 17, 2023 | Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. | ||
| CVE-2023-3591 | Med | 0.31 | 4.8 | 0.00 | Jul 17, 2023 | Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created. | ||
| CVE-2023-2515 | Med | 0.31 | 4.7 | 0.00 | May 12, 2023 | Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin | ||
| CVE-2022-1384 | Med | 0.31 | 4.7 | 0.01 | Apr 19, 2022 | Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known… | ||
| CVE-2021-37866 | Med | 0.31 | 4.7 | 0.01 | Jan 18, 2022 | Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization. |
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.
- risk 0.33cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.
- risk 0.32cvss 4.9epss 0.00
Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589
- risk 0.32cvss 4.9epss 0.00
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.
- risk 0.31cvss 5.9epss 0.00
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests…
- risk 0.31cvss 5.8epss 0.00
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin.…
- risk 0.31cvss 5.8epss 0.00
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
- risk 0.31cvss 4.7epss 0.00
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to…
- risk 0.31cvss 4.7epss 0.00
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
- risk 0.31cvss 4.8epss 0.00
Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
- risk 0.31cvss 4.7epss 0.00
Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin
- risk 0.31cvss 4.7epss 0.01
Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known…
- risk 0.31cvss 4.7epss 0.01
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.
Page 11 of 29