VYPR

Vendor CVEs

Mattermost

All CVEs

614 total · sorted by risk
  • CVE-2023-2000MedMay 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website

  • CVE-2022-0903MedMar 10, 2022
    risk 0.35cvss 5.3epss 0.01

    A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.

  • CVE-2017-18919MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.

  • CVE-2017-18914MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist.

  • CVE-2016-11078MedJun 19, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.

  • CVE-2016-11072MedJun 19, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.

  • CVE-2017-18902MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.

  • CVE-2017-18899MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.

  • CVE-2017-18887MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.

  • CVE-2017-18874MedJun 19, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.

  • CVE-2019-20884MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post.

  • CVE-2019-20882MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.

  • CVE-2019-20877MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.

  • CVE-2019-20876MedJun 19, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.

  • CVE-2019-20875MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.

  • CVE-2018-21265MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

  • CVE-2018-21259MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.

  • CVE-2018-21257MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.

  • CVE-2020-14452MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.

  • CVE-2019-20850MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.

  • CVE-2019-20849MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.

  • CVE-2019-20847MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any channel.

  • CVE-2025-27936MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin…

  • CVE-2024-42411MedAug 22, 2024
    risk 0.34cvss 5.3epss 0.00

    Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

  • CVE-2024-6428MedJul 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause…

  • CVE-2023-6459MedDec 6, 2023
    risk 0.34cvss 5.3epss 0.01

    Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

  • CVE-2025-54458MedAug 11, 2025
    risk 0.33cvss 5.0epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.

  • CVE-2017-18907MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.

  • CVE-2016-11084MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.00

    An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.

  • CVE-2016-11083MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.

  • CVE-2016-11082MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.

  • CVE-2016-11079MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.

  • CVE-2016-11073MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.

  • CVE-2016-11071MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.

  • CVE-2016-11063MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.

  • CVE-2017-18904MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.

  • CVE-2017-18897MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.

  • CVE-2017-18893MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.

  • CVE-2017-18892MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.

  • CVE-2026-3116MedMar 26, 2026
    risk 0.32cvss 4.9epss 0.00

    Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589

  • CVE-2023-5193MedSep 29, 2023
    risk 0.32cvss 4.9epss 0.00

    Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.

  • CVE-2026-3473MedMay 22, 2026
    risk 0.31cvss 5.9epss 0.00

    Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests…

  • CVE-2026-2454MedMar 16, 2026
    risk 0.31cvss 5.8epss 0.00

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin.…

  • CVE-2025-31947MedMay 15, 2025
    risk 0.31cvss 5.8epss 0.00

    Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.

  • CVE-2024-8071MedAug 22, 2024
    risk 0.31cvss 4.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to…

  • CVE-2023-5339MedOct 17, 2023
    risk 0.31cvss 4.7epss 0.00

    Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 

  • CVE-2023-3591MedJul 17, 2023
    risk 0.31cvss 4.8epss 0.00

    Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.

  • CVE-2023-2515MedMay 12, 2023
    risk 0.31cvss 4.7epss 0.00

    Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin

  • CVE-2022-1384MedApr 19, 2022
    risk 0.31cvss 4.7epss 0.01

    Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known…

  • CVE-2021-37866MedJan 18, 2022
    risk 0.31cvss 4.7epss 0.01

    Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.

Page 5 of 13