VYPR

Mattermost

by Mattermost

Source repositories

CVEs (566)

  • CVE-2019-20844MedJun 19, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel.

  • CVE-2023-4106MedAug 11, 2023
    risk 0.41cvss 6.3epss 0.00

    Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.

  • CVE-2025-14273HigDec 22, 2025
    risk 0.40cvss 7.2epss 0.00

    Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an…

  • CVE-2025-59480MedNov 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses

  • CVE-2025-55035MedOct 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the…

  • CVE-2024-2445MedMar 15, 2024
    risk 0.40cvss 6.1epss 0.00

    Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site…

  • CVE-2023-3581MedJul 17, 2023
    risk 0.40cvss 6.2epss 0.00

    Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.

  • CVE-2023-2788MedJun 16, 2023
    risk 0.40cvss 6.2epss 0.01

    Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

  • CVE-2017-18921MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.

  • CVE-2017-18913MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.

  • CVE-2017-18882MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.

  • CVE-2017-18881MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.

  • CVE-2017-18880MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.

  • CVE-2017-18879MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.

  • CVE-2017-18877MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.

  • CVE-2024-42497MedAug 22, 2024
    risk 0.39cvss 6.0epss 0.00

    Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.

  • CVE-2024-32045MedMay 26, 2024
    risk 0.38cvss 5.9epss 0.00

    Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members of.

  • CVE-2021-37861MedDec 9, 2021
    risk 0.38cvss 5.8epss 0.01

    Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

  • CVE-2026-6739MedJun 12, 2026
    risk 0.37cvss 6.7epss 0.00

    Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patching protected default system roles, which allows authenticated users with delegated user-management permissions to escalate…

  • CVE-2026-28741MedApr 15, 2026
    risk 0.37cvss 6.8epss 0.00

    Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's authentication method via a CSRF attack by tricking a user into visiting a…

Page 7 of 29