VYPR

Vendor CVEs

Mattermost

All CVEs

614 total · sorted by risk
  • CVE-2026-9824MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster…

  • CVE-2026-9820LowJul 13, 2026
    risk 0.00cvss 3.8epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the…

  • CVE-2026-6541MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or…

  • CVE-2026-9708MedJul 13, 2026
    risk 0.00cvss 4.9epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages…

  • CVE-2026-9597MedJul 13, 2026
    risk 0.00cvss 5.4epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued…

  • CVE-2026-9571MedJul 13, 2026
    risk 0.00cvss 5.9epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via…

  • CVE-2026-6850MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a…

  • CVE-2026-9699MedJun 26, 2026
    risk 0.00cvss 6.8epss 0.00

    Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of…

  • CVE-2026-4339MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform…

  • CVE-2026-3472LowJun 26, 2026
    risk 0.00cvss 3.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown…

  • CVE-2026-13426MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal…

  • CVE-2022-1982MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

  • CVE-2017-18891MedJun 19, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.

  • CVE-2020-14457MedJun 19, 2020
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka MMSA-2020-0012.

Page 13 of 13