VYPR

Mattermost

by Mattermost

Source repositories

CVEs (594)

  • CVE-2024-29221MedApr 5, 2024
    risk 0.24cvss 4.7epss 0.00

    Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing…

  • CVE-2023-7113LowDec 29, 2023
    risk 0.24cvss 3.7epss 0.00

    Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.

  • CVE-2023-6547LowDec 12, 2023
    risk 0.24cvss 3.7epss 0.00

    Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team,…

  • CVE-2022-1385LowApr 19, 2022
    risk 0.24cvss 3.7epss 0.01

    Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.

  • CVE-2021-37862LowDec 17, 2021
    risk 0.24cvss 3.7epss 0.01

    Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.

  • CVE-2021-37860LowSep 22, 2021
    risk 0.24cvss 3.7epss 0.01

    Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.

  • CVE-2018-21249LowJun 19, 2020
    risk 0.24cvss 3.7epss 0.01

    An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing.

  • CVE-2026-27659MedMar 25, 2026
    risk 0.23cvss 4.6epss 0.00

    Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate CSRF tokens in the /api/v4/access_control_policies/{policy_id}/activate endpoint, which allows an attacker to trick an admin into changing access control…

  • CVE-2025-58084LowOct 13, 2025
    risk 0.23cvss 3.5epss 0.00

    Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.

  • CVE-2024-46872MedOct 29, 2024
    risk 0.23cvss 4.6epss 0.00

    Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks

  • CVE-2024-40886MedAug 22, 2024
    risk 0.23cvss 4.6epss 0.00

    Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in User Management page of the system…

  • CVE-2023-3613LowJul 17, 2023
    risk 0.23cvss 3.5epss 0.00

    Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowing guest accounts to be added or invited to channels by default.

  • CVE-2023-3577LowJul 17, 2023
    risk 0.23cvss 3.5epss 0.00

    Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an attacker to perform a limited blind SSRF.

  • CVE-2023-1562LowMar 22, 2023
    risk 0.23cvss 3.5epss 0.00

    Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.

  • CVE-2023-1421LowMar 15, 2023
    risk 0.23cvss 3.5epss 0.00

    A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.

  • CVE-2021-37863LowDec 17, 2021
    risk 0.23cvss 3.5epss 0.01

    Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.

  • CVE-2026-86349MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU resource exhaustion) via a crafted post…

  • CVE-2026-86348MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA-2026-00701

  • CVE-2026-14344MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-and-blocks, and archive-import endpoints..…

  • CVE-2026-14259MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator…

Page 20 of 30