VYPR

Mattermost

by Mattermost

Source repositories

CVEs (594)

  • CVE-2023-5193MedSep 29, 2023
    risk 0.32cvss 4.9epss 0.00

    Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.

  • CVE-2026-3473MedMay 22, 2026
    risk 0.31cvss 5.9epss 0.00

    Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests…

  • CVE-2026-2454MedMar 16, 2026
    risk 0.31cvss 5.8epss 0.00

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin.…

  • CVE-2025-31947MedMay 15, 2025
    risk 0.31cvss 5.8epss 0.00

    Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.

  • CVE-2024-8071MedAug 22, 2024
    risk 0.31cvss 4.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to…

  • CVE-2023-5339MedOct 17, 2023
    risk 0.31cvss 4.7epss 0.00

    Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 

  • CVE-2023-3591MedJul 17, 2023
    risk 0.31cvss 4.8epss 0.00

    Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.

  • CVE-2023-2515MedMay 12, 2023
    risk 0.31cvss 4.7epss 0.00

    Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin

  • CVE-2022-1384MedApr 19, 2022
    risk 0.31cvss 4.7epss 0.01

    Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known…

  • CVE-2021-37866MedJan 18, 2022
    risk 0.31cvss 4.7epss 0.01

    Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.

  • CVE-2026-27656MedMar 25, 2026
    risk 0.30cvss 5.7epss 0.00

    Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring…

  • CVE-2026-1628MedMar 2, 2026
    risk 0.30cvss 4.6epss 0.00

    Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their…

  • CVE-2025-13821MedFeb 16, 2026
    risk 0.30cvss 5.7epss 0.00

    Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost…

  • CVE-2024-12247MedDec 5, 2024
    risk 0.30cvss 4.6epss 0.00

    Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.

  • CVE-2026-82920MedSep 14, 2026
    risk 0.29cvss 5.5epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy via a crafted PUT…

  • CVE-2024-45833MedSep 16, 2024
    risk 0.29cvss 4.5epss 0.00

    Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the…

  • CVE-2024-41144MedAug 1, 2024
    risk 0.29cvss 5.5epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled,  which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels

  • CVE-2023-4108MedAug 11, 2023
    risk 0.29cvss 4.5epss 0.01

    Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

  • CVE-2019-20860MedJun 19, 2020
    risk 0.29cvss 5.5epss 0.01

    An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.

  • CVE-2026-16049MedAug 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance,…

Page 12 of 30