VYPR

Vendor CVEs

Mattermost

All CVEs

649 total · sorted by risk
  • CVE-2025-62690LowDec 17, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.

  • CVE-2025-13352LowDec 17, 2025
    risk 0.13cvss 3.0epss 0.00

    Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted…

  • CVE-2025-13870LowDec 2, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards…

  • CVE-2025-55074LowNov 18, 2025
    risk 0.13cvss 3.0epss 0.00

    Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects

  • CVE-2025-41436LowNov 14, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

  • CVE-2025-11777LowNov 13, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint

  • CVE-2025-54499LowOct 16, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth…

  • CVE-2025-10545LowOct 16, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint

  • CVE-2025-9081LowSep 19, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration

  • CVE-2025-9084LowSep 15, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs

  • CVE-2025-4128LowJun 11, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.

  • CVE-2025-3611LowMay 30, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct…

  • CVE-2025-1792LowMay 30, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members…

  • CVE-2025-41423LowApr 24, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the…

  • CVE-2025-2424LowApr 14, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.

  • CVE-2025-1412LowFeb 24, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

  • CVE-2024-47003LowSep 26, 2024
    risk 0.13cvss 3.1epss 0.01

    Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a permalink post and crash the frontend.

  • CVE-2024-39807LowJul 3, 2024
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.

  • CVE-2024-39361LowJul 3, 2024
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can…

  • CVE-2024-22091LowApr 26, 2024
    risk 0.13cvss 3.1epss 0.01

    Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request…

  • CVE-2024-28053LowMar 15, 2024
    risk 0.13cvss 3.1epss 0.01

    Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.

  • CVE-2022-1002LowMar 18, 2022
    risk 0.13cvss 2.0epss 0.01

    Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.

  • CVE-2026-27769LowApr 15, 2026
    risk 0.11cvss 2.7epss 0.00

    Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected…

  • CVE-2024-40884LowAug 22, 2024
    risk 0.11cvss 2.7epss 0.00

    Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.

  • CVE-2024-41926LowAug 1, 2024
    risk 0.11cvss 2.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another…

  • CVE-2024-39353LowJul 3, 2024
    risk 0.11cvss 2.7epss 0.00

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.

  • CVE-2024-4198LowApr 26, 2024
    risk 0.11cvss 2.7epss 0.01

    Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.

  • CVE-2024-4195LowApr 26, 2024
    risk 0.11cvss 2.7epss 0.01

    Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.

  • CVE-2016-11077LowJun 19, 2020
    risk 0.11cvss 2.7epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.

  • CVE-2026-75588LowSep 17, 2026
    risk 0.10cvss 2.6epss 0.00

    Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a…

  • CVE-2025-6227LowJul 18, 2025
    risk 0.07cvss 2.2epss 0.00

    Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.

  • CVE-2025-30516LowApr 14, 2025
    risk 0.06cvss 2.0epss 0.00

    Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications

  • CVE-2026-7521MedJul 28, 2026
    risk 0.00cvss 5.5epss 0.00

    Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove…

  • CVE-2026-9602MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost…

  • CVE-2026-8075MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image that misses one of…

  • CVE-2026-9824MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster…

  • CVE-2026-9820LowJul 13, 2026
    risk 0.00cvss 3.8epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the…

  • CVE-2026-6541MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or…

  • CVE-2026-9708MedJul 13, 2026
    risk 0.00cvss 4.9epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages…

  • CVE-2026-9597MedJul 13, 2026
    risk 0.00cvss 5.4epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued…

  • CVE-2026-9571MedJul 13, 2026
    risk 0.00cvss 5.9epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via…

  • CVE-2026-6850MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a…

  • CVE-2026-9699MedJun 26, 2026
    risk 0.00cvss 6.8epss 0.00

    Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of…

  • CVE-2026-4339MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform…

  • CVE-2026-3472LowJun 26, 2026
    risk 0.00cvss 3.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown…

  • CVE-2026-13426MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal…

  • CVE-2022-1982MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

  • CVE-2017-18891MedJun 19, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.

  • CVE-2020-14457MedJun 19, 2020
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka MMSA-2020-0012.

Page 13 of 13