VYPR

Mattermost

by Mattermost

Source repositories

CVEs (594)

  • CVE-2025-64641MedDec 24, 2025
    risk 0.20cvss 4.1epss 0.00

    Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users…

  • CVE-2025-4573MedJun 11, 2025
    risk 0.20cvss 4.1epss 0.00

    Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter…

  • CVE-2025-2571MedMay 30, 2025
    risk 0.20cvss 4.2epss 0.00

    Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.

  • CVE-2025-31363LowApr 16, 2025
    risk 0.20cvss 3.0epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt…

  • CVE-2025-24839LowApr 16, 2025
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override property to a post via the…

  • CVE-2025-0503LowFeb 14, 2025
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.

  • CVE-2024-36250LowNov 9, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds

  • CVE-2024-47145LowSep 26, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.

  • CVE-2024-45843LowSep 26, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.

  • CVE-2024-41162MedAug 1, 2024
    risk 0.20cvss 4.1epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.

  • CVE-2024-39767MedJul 15, 2024
    risk 0.20cvss 4.2epss 0.00

    Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in…

  • CVE-2024-36241LowMay 26, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command

  • CVE-2024-3872LowApr 16, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.

  • CVE-2024-21848LowApr 5, 2024
    risk 0.20cvss 3.1epss 0.00

    Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel

  • CVE-2024-1952LowFeb 29, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member…

  • CVE-2024-23488LowFeb 29, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled.

  • CVE-2024-24776LowFeb 9, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.

  • CVE-2023-6727LowDec 12, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some…

  • CVE-2023-35075LowNov 27, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though. 

  • CVE-2023-5876LowNov 2, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.

Page 25 of 30