VYPR

Mattermost

by Mattermost

Source repositories

CVEs (594)

  • CVE-2023-5194LowSep 29, 2023
    risk 0.18cvss 2.7epss 0.00

    Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager

  • CVE-2023-3587LowJul 17, 2023
    risk 0.18cvss 2.7epss 0.00

    Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions.

  • CVE-2023-27266LowFeb 27, 2023
    risk 0.18cvss 2.7epss 0.01

    Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

  • CVE-2023-27265LowFeb 27, 2023
    risk 0.18cvss 2.7epss 0.01

    Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

  • CVE-2018-21260LowJun 19, 2020
    risk 0.18cvss 2.7epss 0.01

    An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.

  • CVE-2026-4273LowMay 18, 2026
    risk 0.17cvss 3.7epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token…

  • CVE-2026-24661LowApr 9, 2026
    risk 0.17cvss 3.7epss 0.00

    Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611

  • CVE-2026-21388LowApr 9, 2026
    risk 0.17cvss 3.7epss 0.00

    Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610

  • CVE-2025-13324LowDec 17, 2025
    risk 0.17cvss 3.7epss 0.00

    Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an…

  • CVE-2024-32945LowJul 15, 2024
    risk 0.17cvss 2.6epss 0.00

    Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.

  • CVE-2024-1949LowFeb 29, 2024
    risk 0.17cvss 2.6epss 0.00

    A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.

  • CVE-2023-50333LowJan 2, 2024
    risk 0.17cvss 3.7epss 0.00

    Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.

  • CVE-2021-37864LowJan 18, 2022
    risk 0.17cvss 2.6epss 0.01

    Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

  • CVE-2026-9693LowAug 17, 2026
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post…

  • CVE-2026-6333LowMay 18, 2026
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host…

  • CVE-2025-49810LowAug 21, 2025
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts

  • CVE-2025-47700LowAug 21, 2025
    risk 0.16cvss 3.5epss 0.00

    Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions

  • CVE-2025-22445LowJan 9, 2025
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

  • CVE-2024-10214LowOct 28, 2024
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.

  • CVE-2024-45835LowSep 16, 2024
    risk 0.16cvss 2.5epss 0.00

    Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.

Page 27 of 30