VYPR

Mattermost

by Mattermost

Source repositories

CVEs (566)

  • CVE-2025-14822LowJan 16, 2026
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens

  • CVE-2025-62690LowDec 17, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.

  • CVE-2025-13352LowDec 17, 2025
    risk 0.13cvss 3.0epss 0.00

    Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted…

  • CVE-2025-13870LowDec 2, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards…

  • CVE-2025-55074LowNov 18, 2025
    risk 0.13cvss 3.0epss 0.00

    Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects

  • CVE-2025-41436LowNov 14, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

  • CVE-2025-11777LowNov 13, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint

  • CVE-2025-54499LowOct 16, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth…

  • CVE-2025-10545LowOct 16, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint

  • CVE-2025-9081LowSep 19, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration

  • CVE-2025-9084LowSep 15, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs

  • CVE-2025-4128LowJun 11, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.

  • CVE-2025-3611LowMay 30, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct…

  • CVE-2025-1792LowMay 30, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members…

  • CVE-2025-41423LowApr 24, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the…

  • CVE-2025-2424LowApr 14, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.

  • CVE-2025-1412LowFeb 24, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

  • CVE-2024-47003LowSep 26, 2024
    risk 0.13cvss 3.1epss 0.01

    Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a permalink post and crash the frontend.

  • CVE-2024-39807LowJul 3, 2024
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.

  • CVE-2024-39361LowJul 3, 2024
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can…