VendorsMattermostmattermost_serverall versions
Vulnerabilities

Mattermost Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2023-3591
Lack of previous password reset tokens on new token creation
Published 2023-07-17 · Modified
8.2EPSS 0.003
CVE-2017-18894
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
Published 2020-06-19 · Modified
8.1EPSS 0.008
CVE-2017-18884
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
Published 2020-06-19 · Modified
8.1EPSS 0.008
CVE-2017-18906
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
Published 2020-06-19 · Modified
8.1EPSS 0.008
CVE-2025-58073
Arbitrary Mattermost Team can be joined by manipulating the OAuth state
Published 2025-10-16 · Analyzed
8.1EPSS 0.004
CVE-2025-58075
Arbitrary Mattermost Team can be joined by manipulating the SAML RelayState
Published 2025-10-16 · Analyzed
8.1EPSS 0.003
CVE-2023-3581
WebSockets accept connections from HTTPS origin
Published 2023-07-17 · Modified
8.1EPSS 0.003
CVE-2026-28741
CSRF Protection Bypass Allows Updating a User's Authentication Method
Published 2026-04-15 · Analyzed
8.1EPSS 0.001
CVE-2025-9079
Admin RCE via prepackaged plugins by way of misconfigured imports directory
Published 2025-09-19 · Analyzed
8.0EPSS 0.006
CVE-2026-6961
CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation sync
Published 2026-06-12 · Analyzed
7.6EPSS 0.003
CVE-2026-6347
Mattermost Calls plugin exposes TURN server credentials in plaintext in support packets
Published 2026-05-18 · Analyzed
7.6EPSS 0.003
CVE-2025-9072
One-Click Mattermost Account Takeover via Poisoned RelayState SAML Parameter
Published 2025-09-15 · Analyzed
7.6EPSS 0.002
CVE-2019-20854
An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message.
Published 2020-06-19 · Modified
7.5EPSS 0.013
CVE-2018-21248
An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.
Published 2020-06-19 · Modified
7.5EPSS 0.012
CVE-2019-20859
An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
Published 2020-06-19 · Modified
7.5EPSS 0.012
CVE-2019-20874
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.
Published 2020-06-19 · Modified
7.5EPSS 0.012
CVE-2019-20855
An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration.
Published 2020-06-19 · Modified
7.5EPSS 0.012
CVE-2018-21258
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.
Published 2020-06-19 · Modified
7.5EPSS 0.012
CVE-2016-11066
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2020-14458
An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-0004.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20857
An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown renderer hang) via many backtick characters.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20845
An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack import.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20858
An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20888
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2018-21262
An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2020-14448
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0020.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2020-14447
An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0021.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2020-14450
An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers to cause a denial of service (client-side), aka MMSA-2020-0017.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2017-18871
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20871
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20880
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2015-9548
An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20843
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20885
An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20846
An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20862
An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands.
Published 2020-06-19 · Modified
7.5EPSS 0.009
CVE-2019-20863
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted.
Published 2020-06-19 · Modified
7.5EPSS 0.009
CVE-2019-20868
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
Published 2020-06-19 · Modified
7.5EPSS 0.009
CVE-2020-14459
An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020-0002.
Published 2020-06-19 · Modified
7.5EPSS 0.009
CVE-2016-11069
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
Published 2020-06-19 · Modified
7.5EPSS 0.009
← Prev2 / 12Next →