VYPR

Mattermost

by Mattermost

Source repositories

CVEs (566)

  • CVE-2018-21264HigJun 19, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.

  • CVE-2018-21263HigJun 19, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.

  • CVE-2019-20865HigJun 19, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.

  • CVE-2019-20841HigJun 19, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.

  • CVE-2024-11599HigNov 28, 2024
    risk 0.53cvss 8.2epss 0.00

    Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration.

  • CVE-2023-3615HigJul 17, 2023
    risk 0.53cvss 8.1epss 0.00

    Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.

  • CVE-2017-18894HigJun 19, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.

  • CVE-2017-18884HigJun 19, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.

  • CVE-2026-6957HigMay 27, 2026
    risk 0.52cvss 8.0epss 0.00

    Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary locations within the target…

  • CVE-2017-18911CriJun 19, 2020
    risk 0.52cvss 9.1epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.

  • CVE-2026-7387HigJun 12, 2026
    risk 0.50cvss 8.8epss 0.00

    Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link…

  • CVE-2026-6346HigMay 18, 2026
    risk 0.50cvss 8.7epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermost System Admin or any party with access to a support packet to obtain sensitive…

  • CVE-2024-39777HigAug 1, 2024
    risk 0.50cvss 8.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local…

  • CVE-2024-39274HigAug 1, 2024
    risk 0.50cvss 8.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote to add users to arbitrary…

  • CVE-2017-18903HigJun 19, 2020
    risk 0.50cvss 8.8epss 0.00

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.

  • CVE-2026-1046HigFeb 16, 2026
    risk 0.49cvss 7.6epss 0.00

    Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577

  • CVE-2025-25068HigMar 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.

  • CVE-2020-13891HigJun 26, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, aka MMSA-2020-0022.

  • CVE-2015-9548HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.

  • CVE-2019-20886HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.

Page 2 of 29