VYPR

Vendor CVEs

Mattermost

All CVEs

649 total · sorted by risk
  • CVE-2023-2281LowApr 25, 2023
    risk 0.20cvss 3.1epss 0.00

    When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

  • CVE-2022-4045LowNov 23, 2022
    risk 0.20cvss 3.1epss 0.01

    A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. 

  • CVE-2022-3257LowSep 23, 2022
    risk 0.20cvss 3.1epss 0.01

    Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

  • CVE-2022-3147LowSep 9, 2022
    risk 0.20cvss 3.1epss 0.01

    Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.

  • CVE-2023-5920LowNov 2, 2023
    risk 0.19cvss 2.9epss 0.00

    Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.

  • CVE-2026-8823LowJun 22, 2026
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669

  • CVE-2026-8074LowJun 22, 2026
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT…

  • CVE-2026-3495LowMay 18, 2026
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as…

  • CVE-2026-26230LowMar 16, 2026
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Mattermost Advisory ID: MMSA-2025-00531

  • CVE-2025-14573LowFeb 16, 2026
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561

  • CVE-2025-53971LowAug 21, 2025
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint.

  • CVE-2025-2570LowMay 15, 2025
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console.

  • CVE-2025-24866LowApr 10, 2025
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.11.x <= 9.11.8  fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.

  • CVE-2025-22449LowJan 9, 2025
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

  • CVE-2024-42000LowNov 9, 2024
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels  which allows a User or System Manager, with "Read Groups" permission but with no access for channels to retrieve details…

  • CVE-2024-39837LowAug 1, 2024
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.

  • CVE-2024-29977LowAug 1, 2024
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts

  • CVE-2024-36257LowJul 3, 2024
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one…

  • CVE-2023-5194LowSep 29, 2023
    risk 0.18cvss 2.7epss 0.00

    Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager

  • CVE-2023-3587LowJul 17, 2023
    risk 0.18cvss 2.7epss 0.00

    Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions.

  • CVE-2023-27266LowFeb 27, 2023
    risk 0.18cvss 2.7epss 0.01

    Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

  • CVE-2023-27265LowFeb 27, 2023
    risk 0.18cvss 2.7epss 0.01

    Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

  • CVE-2018-21260LowJun 19, 2020
    risk 0.18cvss 2.7epss 0.01

    An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.

  • CVE-2026-12284LowSep 17, 2026
    risk 0.17cvss 3.7epss 0.00

    Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different…

  • CVE-2026-4273LowMay 18, 2026
    risk 0.17cvss 3.7epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token…

  • CVE-2026-24661LowApr 9, 2026
    risk 0.17cvss 3.7epss 0.00

    Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611

  • CVE-2026-21388LowApr 9, 2026
    risk 0.17cvss 3.7epss 0.00

    Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610

  • CVE-2025-13324LowDec 17, 2025
    risk 0.17cvss 3.7epss 0.00

    Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an…

  • CVE-2024-32945LowJul 15, 2024
    risk 0.17cvss 2.6epss 0.00

    Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.

  • CVE-2024-1949LowFeb 29, 2024
    risk 0.17cvss 2.6epss 0.00

    A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.

  • CVE-2023-50333LowJan 2, 2024
    risk 0.17cvss 3.7epss 0.00

    Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.

  • CVE-2021-37864LowJan 18, 2022
    risk 0.17cvss 2.6epss 0.01

    Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

  • CVE-2026-9693LowAug 17, 2026
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post…

  • CVE-2026-75587LowAug 17, 2026
    risk 0.16cvss 3.6epss 0.00

    Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server…

  • CVE-2026-6333LowMay 18, 2026
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host…

  • CVE-2025-49810LowAug 21, 2025
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts

  • CVE-2025-47700LowAug 21, 2025
    risk 0.16cvss 3.5epss 0.00

    Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions

  • CVE-2025-22445LowJan 9, 2025
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

  • CVE-2024-10214LowOct 28, 2024
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.

  • CVE-2024-45835LowSep 16, 2024
    risk 0.16cvss 2.5epss 0.00

    Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.

  • CVE-2024-23319LowFeb 9, 2024
    risk 0.16cvss 3.5epss 0.00

    Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.

  • CVE-2024-24774LowFeb 9, 2024
    risk 0.15cvss 3.4epss 0.00

    Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues.

  • CVE-2026-3109LowMar 26, 2026
    risk 0.14cvss 2.2epss 0.00

    Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584

  • CVE-2025-13321LowDec 17, 2025
    risk 0.14cvss 3.3epss 0.00

    Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.

  • CVE-2025-27538LowApr 16, 2025
    risk 0.14cvss 2.2epss 0.00

    Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if…

  • CVE-2026-4286LowMay 18, 2026
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing manage members restriction via PUT api.…

  • CVE-2026-6334LowMay 18, 2026
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a different client via a crafted token…

  • CVE-2026-4053LowMay 15, 2026
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update…

  • CVE-2026-22545LowMar 16, 2026
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password without confirmation via falsely claiming a different auth provider.. Mattermost…

  • CVE-2025-14822LowJan 16, 2026
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens

Page 12 of 13