VYPR

Vendor CVEs

Mattermost

All CVEs

649 total · sorted by risk
  • CVE-2025-55070MedNov 14, 2025
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

  • CVE-2025-9076MedSep 15, 2025
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects…

  • CVE-2025-6226MedJul 18, 2025
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the…

  • CVE-2025-41395MedApr 24, 2025
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and…

  • CVE-2025-35965MedApr 24, 2025
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions…

  • CVE-2025-27933MedMar 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public

  • CVE-2024-54682MedDec 16, 2024
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.

  • CVE-2024-54083MedDec 16, 2024
    risk 0.35cvss 6.5epss 0.01

    Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.

  • CVE-2024-42406MedSep 26, 2024
    risk 0.35cvss 5.4epss 0.00

    Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged…

  • CVE-2023-2000MedMay 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website

  • CVE-2022-0903MedMar 10, 2022
    risk 0.35cvss 5.3epss 0.01

    A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.

  • CVE-2017-18919MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.

  • CVE-2017-18914MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist.

  • CVE-2016-11078MedJun 19, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.

  • CVE-2016-11072MedJun 19, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.

  • CVE-2017-18902MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.

  • CVE-2017-18899MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.

  • CVE-2017-18887MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.

  • CVE-2017-18874MedJun 19, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.

  • CVE-2019-20884MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post.

  • CVE-2019-20882MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.

  • CVE-2019-20877MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.

  • CVE-2019-20876MedJun 19, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.

  • CVE-2019-20875MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.

  • CVE-2018-21265MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

  • CVE-2018-21259MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.

  • CVE-2018-21257MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.

  • CVE-2020-14452MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.

  • CVE-2019-20850MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.

  • CVE-2019-20849MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.

  • CVE-2019-20847MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any channel.

  • CVE-2026-16048MedAug 17, 2026
    risk 0.34cvss 6.3epss 0.00

    Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory…

  • CVE-2026-10527MedAug 17, 2026
    risk 0.34cvss 6.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges and perform admin-only operations via the Boards REST API or…

  • CVE-2025-27936MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin…

  • CVE-2024-42411MedAug 22, 2024
    risk 0.34cvss 5.3epss 0.00

    Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

  • CVE-2024-6428MedJul 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause…

  • CVE-2023-6459MedDec 6, 2023
    risk 0.34cvss 5.3epss 0.01

    Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

  • CVE-2025-54458MedAug 11, 2025
    risk 0.33cvss 5.0epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.

  • CVE-2017-18907MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.

  • CVE-2016-11084MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.00

    An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.

  • CVE-2016-11083MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.

  • CVE-2016-11082MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.

  • CVE-2016-11079MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.

  • CVE-2016-11073MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.

  • CVE-2016-11071MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.

  • CVE-2016-11063MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.

  • CVE-2017-18904MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.

  • CVE-2017-18897MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.

  • CVE-2017-18893MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.

  • CVE-2017-18892MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.

Page 5 of 13