VYPR

Mattermost

by Mattermost

Source repositories

CVEs (566)

  • CVE-2026-4339MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform…

  • CVE-2026-3472LowJun 26, 2026
    risk 0.00cvss 3.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown…

  • CVE-2026-13426MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal…

  • CVE-2022-1982MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

  • CVE-2017-18891MedJun 19, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.

  • CVE-2020-14457MedJun 19, 2020
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka MMSA-2020-0012.

Page 29 of 29