VendorsMattermostmattermost_serverall versions
Vulnerabilities

Mattermost Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2019-20886
An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.
Published 2020-06-19 · Modified
7.5EPSS 0.009
CVE-2019-20881
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
Published 2020-06-19 · Modified
7.5EPSS 0.008
CVE-2022-0903
Stack overflow in SAML login in Mattermost
Published 2022-03-09 · Modified
7.5EPSS 0.008
CVE-2017-18917
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.
Published 2020-06-19 · Modified
7.5EPSS 0.007
CVE-2017-18909
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
Published 2020-06-19 · Modified
7.5EPSS 0.007
CVE-2023-49607
Playbook plugin crash via missing interface type assertion
Published 2023-12-12 · Modified
7.5EPSS 0.006
CVE-2023-45847
Playbook Plugin Crash via Run Checklist
Published 2023-12-12 · Modified
7.5EPSS 0.006
CVE-2020-14453
An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005.
Published 2020-06-19 · Modified
7.5EPSS 0.006
CVE-2026-5740
Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server
Published 2026-05-22 · Analyzed
7.5EPSS 0.006
CVE-2023-5330
Denial of Service via Opengraph Data Cache
Published 2023-10-09 · Modified
7.5EPSS 0.005
CVE-2025-41395
Webapp DoS via malicious retrospective post in Playbooks
Published 2025-04-24 · Analyzed
7.5EPSS 0.005
CVE-2024-47401
DoS via Amplified GraphQL Response in Playbooks
Published 2024-10-29 · Analyzed
7.5EPSS 0.005
CVE-2025-20621
Webapp crash via object that can't be cast to String in Attachment Field
Published 2025-01-16 · Analyzed
7.5EPSS 0.005
CVE-2026-5308
Missing request body size limits on Zoom plugin HTTP endpoints
Published 2026-05-22 · Analyzed
7.5EPSS 0.004
CVE-2023-3590
Deleted attachments in Boards remain accessible
Published 2023-07-17 · Modified
7.5EPSS 0.004
CVE-2023-1831
User password logged in audit logs
Published 2023-04-17 · Modified
7.5EPSS 0.004
CVE-2025-35965
DoS in Mattermost Playbooks via Excessive Task Actions
Published 2025-04-24 · Analyzed
7.5EPSS 0.004
CVE-2026-20719
DoS via URL Previews Rendering Malicious SVGs
Published 2026-03-25 · Analyzed
7.5EPSS 0.004
CVE-2025-55070
Lack of MFA enforcement in WebSocket connections
Published 2025-11-14 · Analyzed
7.5EPSS 0.003
CVE-2026-24458
DoS attack via login attempts with multi-megabyte passwords
Published 2026-03-16 · Analyzed
7.5EPSS 0.003
CVE-2023-1776
Stored XSS via SVG attachment on Boards
Published 2023-03-31 · Modified
7.3EPSS 0.004
CVE-2019-20842
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by admins via SearchAllChannels.
Published 2020-06-19 · Modified
7.2EPSS 0.010
CVE-2026-6739
Mattermost: Delegated admins could patch protected default system roles
Published 2026-06-12 · Analyzed
7.2EPSS 0.005
CVE-2024-41144
Malicious remote can create/update/delete arbitrary posts in arbitrary channels
Published 2024-08-01 · Analyzed
7.1EPSS 0.004
CVE-2026-3473
Improper file ownership validation in the Boards API allows unauthorised file access
Published 2026-05-22 · Analyzed
7.1EPSS 0.002
CVE-2025-36530
Import Path Traversal Enables Unauthorized Unsigned Plugin Installation
Published 2025-08-21 · Analyzed
6.8EPSS 0.005
CVE-2026-3112
Arbitrary File Read via Advanced Logging Support Packet
Published 2026-03-26 · Analyzed
6.8EPSS 0.005
CVE-2025-8023
Path Traversal in Template Upload Allows Uploading Files Outside Target Directory
Published 2025-08-21 · Analyzed
6.8EPSS 0.004
CVE-2025-6233
Arbitrary file read by system admin via path traversal
Published 2025-07-18 · Analyzed
6.8EPSS 0.004
CVE-2025-14435
Application-Level DoS via infinite re-render loop in user profile handling
Published 2026-01-16 · Analyzed
6.8EPSS 0.003
CVE-2025-49222
Mattermost Shared Channel Upload Type Validation Bypass
Published 2025-08-21 · Analyzed
6.8EPSS 0.003
CVE-2026-2462
Admin RCE via Malicious Plugin Upload on CI Test Instances
Published 2026-03-16 · Analyzed
6.6EPSS 0.003
CVE-2022-3257
Server-side Denial of Service while processing a specifically crafted GIF file
Published 2022-09-23 · Modified
6.5EPSS 0.013
CVE-2017-18874
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
Published 2020-06-19 · Modified
6.5EPSS 0.012
CVE-2018-21250
An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions.
Published 2020-06-19 · Modified
6.5EPSS 0.011
CVE-2022-3147
Server-side Denial of Service while processing a specifically crafted JPEG file
Published 2022-09-09 · Modified
6.5EPSS 0.010
CVE-2016-11078
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.
Published 2020-06-19 · Modified
6.5EPSS 0.009
CVE-2019-20873
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation.
Published 2020-06-19 · Modified
6.5EPSS 0.009
CVE-2022-0904
Stack overflow in document extractor in Mattermost
Published 2022-03-09 · Modified
6.5EPSS 0.009
CVE-2022-1337
OOM DoS in Mattermost image proxy
Published 2022-04-13 · Modified
6.5EPSS 0.009
← Prev3 / 12Next →