VYPR

Mattermost

by Mattermost

Source repositories

CVEs (566)

  • CVE-2022-3257LowSep 23, 2022
    risk 0.20cvss 3.1epss 0.01

    Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

  • CVE-2022-3147LowSep 9, 2022
    risk 0.20cvss 3.1epss 0.01

    Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.

  • CVE-2026-3495LowMay 18, 2026
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as…

  • CVE-2026-26230LowMar 16, 2026
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Mattermost Advisory ID: MMSA-2025-00531

  • CVE-2025-14573LowFeb 16, 2026
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561

  • CVE-2025-53971LowAug 21, 2025
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint.

  • CVE-2025-2570LowMay 15, 2025
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console.

  • CVE-2025-24866LowApr 10, 2025
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.11.x <= 9.11.8  fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.

  • CVE-2025-22449LowJan 9, 2025
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

  • CVE-2024-42000LowNov 9, 2024
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels  which allows a User or System Manager, with "Read Groups" permission but with no access for channels to retrieve details…

  • CVE-2024-39837LowAug 1, 2024
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.

  • CVE-2024-29977LowAug 1, 2024
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts

  • CVE-2024-36257LowJul 3, 2024
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one…

  • CVE-2023-5194LowSep 29, 2023
    risk 0.18cvss 2.7epss 0.00

    Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager

  • CVE-2023-3587LowJul 17, 2023
    risk 0.18cvss 2.7epss 0.00

    Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions.

  • CVE-2023-27266LowFeb 27, 2023
    risk 0.18cvss 2.7epss 0.01

    Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

  • CVE-2023-27265LowFeb 27, 2023
    risk 0.18cvss 2.7epss 0.01

    Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

  • CVE-2018-21260LowJun 19, 2020
    risk 0.18cvss 2.7epss 0.01

    An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.

  • CVE-2026-4273LowMay 18, 2026
    risk 0.17cvss 3.7epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token…

  • CVE-2026-24661LowApr 9, 2026
    risk 0.17cvss 3.7epss 0.00

    Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611

Page 25 of 29