VendorsMattermostmattermost_serverall versions
Vulnerabilities

Mattermost Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2025-4128
Mattermost Guest User Information Disclosure Vulnerability
Published 2025-06-11 · Analyzed
4.3EPSS 0.002
CVE-2025-47870
Team invite ID leaked to team admin with no member invite privileges
Published 2025-08-21 · Analyzed
4.3EPSS 0.002
CVE-2025-12559
Information Disclosure in Common Teams API
Published 2025-11-27 · Analyzed
4.3EPSS 0.002
CVE-2025-49810
Thread summarization allows persistent access to channel
Published 2025-08-21 · Analyzed
4.3EPSS 0.002
CVE-2026-1629
Permalink Preview Information Disclosure After Permission Revocation
Published 2026-03-16 · Analyzed
4.3EPSS 0.002
CVE-2025-11776
Guest user can discover archived public channels
Published 2025-11-14 · Analyzed
4.3EPSS 0.002
CVE-2025-13767
Unauthorized Read Access to Private Channel Posts via Mattermost Jira Plugin
Published 2025-12-24 · Analyzed
4.3EPSS 0.002
CVE-2026-21386
Private channel enumeration via /mute slash command
Published 2026-03-16 · Analyzed
4.3EPSS 0.002
CVE-2025-11777
Cross-team channel membership access
Published 2025-11-13 · Analyzed
4.3EPSS 0.002
CVE-2025-12756
Insecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment Deletion
Published 2025-12-01 · Analyzed
4.3EPSS 0.002
CVE-2024-41926
Malicious remote can claim that a user was synced from another remote
Published 2024-08-01 · Analyzed
4.3EPSS 0.002
CVE-2026-2463
Unauthorized access to invite ID during team creation
Published 2026-03-16 · Analyzed
4.3EPSS 0.002
CVE-2025-41436
Unauthorized access to archived channel content via threads interface
Published 2025-11-14 · Analyzed
4.3EPSS 0.002
CVE-2025-14350
Information disclosure via channel mentions in posts
Published 2026-02-16 · Analyzed
4.3EPSS 0.002
CVE-2026-24692
Guest users can bypass read permissions via search API
Published 2026-03-16 · Analyzed
4.3EPSS 0.002
CVE-2026-2455
SSRF bypass via IPv4-mapped IPv6 literals
Published 2026-03-16 · Analyzed
4.3EPSS 0.002
CVE-2026-2458
Unauthorized channel enumeration in private teams after member removal
Published 2026-03-16 · Analyzed
4.3EPSS 0.002
CVE-2026-2461
Missing authorization check allows unauthorized modification of other users' comments on a board
Published 2026-03-16 · Analyzed
4.3EPSS 0.002
CVE-2026-0997
Mattermost Zoom Plugin channel preference API lacks authorization checks
Published 2026-02-16 · Analyzed
4.3EPSS 0.002
CVE-2026-0998
Mattermost Zoom Plugin allows unauthorized meeting creation and post modification via insufficient API access controls
Published 2026-02-16 · Analyzed
4.3EPSS 0.002
CVE-2026-6339
Missing request origin validation on burn-on-read reveal endpoint
Published 2026-05-18 · Analyzed
4.3EPSS 0.002
CVE-2025-9078
Weak cache keys lead to post IDOR and link preview poisoning
Published 2025-09-15 · Analyzed
4.3EPSS 0.002
CVE-2025-62190
CSRF Allows Call Initiation and Message Delivery
Published 2025-12-17 · Analyzed
4.3EPSS 0.001
CVE-2026-2457
WebSocket Message Spoofing via Permalink Embed Manipulation
Published 2026-03-16 · Analyzed
4.3EPSS 0.001
CVE-2026-15754
Missing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removal
Published 2026-08-17 · Analyzed
4.2EPSS 0.002
CVE-2025-2571
Google OAuth Authentication Bypass for Converted Bot Accounts
Published 2025-05-30 · Analyzed
4.2EPSS 0.002
CVE-2024-24774
Missing authorization allows users to access arbitrary security levels on Jira through webhooks (Jira Plugin)
Published 2024-02-09 · Modified
4.1EPSS 0.005
CVE-2025-4573
LDAP Injection in Mattermost Enterprise Edition When Using Active Directory
Published 2025-06-11 · Analyzed
4.1EPSS 0.003
CVE-2025-64641
Mattermost Jira plugin crafted action leaks Jira issue details
Published 2025-12-24 · Analyzed
4.1EPSS 0.002
CVE-2018-21260
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.
Published 2020-06-19 · Modified
4.0EPSS 0.007
CVE-2016-11077
An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.
Published 2020-06-19 · Modified
4.0EPSS 0.006
CVE-2026-8823
User Manager can demote bot accounts to guest without bot-management permission
Published 2026-06-22 · Analyzed
3.8EPSS 0.003
CVE-2026-8074
Improper Permission Check Allows User Manager to Deactivate Bot Accounts
Published 2026-06-22 · Analyzed
3.8EPSS 0.003
CVE-2025-22449
Access control flaw for team admins allows unauthorized team additions
Published 2025-01-09 · Analyzed
3.8EPSS 0.003
CVE-2026-26230
Team Admin Privilege Escalation to Demote Members to Guest
Published 2026-03-16 · Analyzed
3.8EPSS 0.003
CVE-2026-9820
Mattermost schemes teams endpoint exposes private team invite IDs
Published 2026-07-13 · Analyzed
3.8EPSS 0.003
CVE-2025-53971
Channel and Team Membership APIs inadvertently allow loss of Member privileges.
Published 2025-08-21 · Analyzed
3.8EPSS 0.002
CVE-2026-6334
OAuth authorization code client binding not enforced during token redemption in Mattermost
Published 2026-05-18 · Analyzed
3.8EPSS 0.002
CVE-2025-14573
Team Admin Bypass of Invite Permissions via allow_open_invite Field
Published 2026-02-16 · Analyzed
3.8EPSS 0.002
CVE-2025-54499
Insecure string comparison enables timing attacks
Published 2025-10-16 · Analyzed
3.7EPSS 0.003
← Prev11 / 12Next →