VendorsMattermostmattermost_serverall versions
Vulnerabilities

Mattermost Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2025-13324
Lack of Invalidation of Legacy Remote Cluster Invite Tokens After Confirmation
Published 2025-12-17 · Analyzed
3.7EPSS 0.002
CVE-2023-3613
Guest accounts invited and added to channels by Welcomebot plugin
Published 2023-07-17 · Modified
3.5EPSS 0.003
CVE-2026-9693
Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite
Published 2026-08-17 · Analyzed
3.5EPSS 0.003
CVE-2026-3472
Markdown image rendering bypass in AI bot tool result posts in Mattermost
Published 2026-06-26 · Analyzed
3.5EPSS 0.003
CVE-2024-23319
CSRF issue allows disconnecting a user's Jira connection through a simple post message (Jira Plugin)
Published 2024-02-09 · Modified
3.5EPSS 0.002
CVE-2025-47700
AI plugin APIs can be triggered using post actions
Published 2025-08-21 · Analyzed
3.5EPSS 0.002
CVE-2025-55074
Channel member objects leak read status
Published 2025-11-18 · Analyzed
3.5EPSS 0.002
CVE-2026-22545
Password Change Bypass via Auth Switch Endpoint
Published 2026-03-16 · Analyzed
3.5EPSS 0.001
CVE-2025-27715
Auto-Enrollment of Team Admins into Private Channels without explicit consent
Published 2025-03-21 · Analyzed
3.3EPSS 0.002
CVE-2023-3584
Member can create team with team override scheme
Published 2023-07-17 · Modified
3.1EPSS 0.004
CVE-2024-21848
Users maintain access to active call after being removed from a channel
Published 2024-04-05 · Analyzed
3.1EPSS 0.003
CVE-2025-1792
Improper Access Control in Mattermost Channel Member API
Published 2025-05-30 · Analyzed
3.1EPSS 0.002
CVE-2026-20796
Time-of-check time-of-use vulnerability in common teams API
Published 2026-02-13 · Analyzed
3.1EPSS 0.002
CVE-2025-6227
Invite token is used as part of the secure communication
Published 2025-07-18 · Analyzed
3.1EPSS 0.002
CVE-2025-13352
Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking
Published 2025-12-17 · Analyzed
3.0EPSS 0.002
CVE-2023-27265
Disclosure of team owner email address when regenerating Invite ID
Published 2023-02-27 · Modified
2.7EPSS 0.005
CVE-2023-27266
Disclosure of team owner email address when when accessing the teams API
Published 2023-02-27 · Modified
2.7EPSS 0.005
CVE-2024-4198
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
Published 2024-04-26 · Analyzed
2.7EPSS 0.005
CVE-2024-4195
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
Published 2024-04-26 · Analyzed
2.7EPSS 0.005
CVE-2023-3587
Inconsistent state in UI after boards permission change by system admin
Published 2023-07-17 · Modified
2.7EPSS 0.004
CVE-2024-40884
Unauthorized disabling of invite URL
Published 2024-08-22 · Analyzed
2.7EPSS 0.004
CVE-2025-2570
System Admin Cannot Access Environment settings in System Console While System Manager Can
Published 2025-05-15 · Analyzed
2.7EPSS 0.003
CVE-2025-24866
Unauthorized Access to User Activity Logs API by delegated granular administration roles
Published 2025-04-10 · Analyzed
2.7EPSS 0.003
CVE-2026-27769
Connected Workspaces: Malicious remote server can manipulate arbitrary user's status
Published 2026-04-15 · Analyzed
2.7EPSS 0.003
CVE-2025-27538
MFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other Users
Published 2025-04-16 · Analyzed
2.7EPSS 0.002
CVE-2024-1949
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.
Published 2024-02-29 · Analyzed
2.6EPSS 0.003
CVE-2026-3109
Missing timestamp validation in Zoom webhook handler
Published 2026-03-26 · Analyzed
2.2EPSS 0.003
← Prev12 / 12