VendorsMattermostmattermost_serverall versions
Vulnerabilities

Mattermost Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2022-1982
A crafted SVG attachment can crash a Mattermost server
Published 2022-06-02 · Modified
6.5EPSS 0.009
CVE-2022-2401
Team members could access sensitive information of other users via an API call
Published 2022-07-14 · Modified
6.5EPSS 0.008
CVE-2020-14460
An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAuth application does not always require admin privileges, aka MMSA-2020-0001.
Published 2020-06-19 · Modified
6.5EPSS 0.008
CVE-2016-11072
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
Published 2020-06-19 · Modified
6.5EPSS 0.007
CVE-2024-24988
Excessive resource consumption when sending long emoji names in user custom status
Published 2024-02-29 · Analyzed
6.5EPSS 0.007
CVE-2023-49809
Todo plugin gets crashed and disabled by member
Published 2023-12-12 · Modified
6.5EPSS 0.006
CVE-2024-54083
DoS via lack of type validation in Calls
Published 2024-12-16 · Analyzed
6.5EPSS 0.006
CVE-2025-20033
DoS via custom post type for sysconsole plugin readers
Published 2025-01-09 · Analyzed
6.5EPSS 0.006
CVE-2024-4183
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
Published 2024-04-26 · Analyzed
6.5EPSS 0.006
CVE-2023-3593
Server crash via a specially crafted markdown input
Published 2023-07-17 · Modified
6.5EPSS 0.006
CVE-2024-47003
DoS via non-string message using permalink embed
Published 2024-09-26 · Analyzed
6.5EPSS 0.006
CVE-2024-28949
DoS via a large number of User Preferences
Published 2024-04-05 · Analyzed
6.5EPSS 0.006
CVE-2025-20088
Insufficient Input Validation on Post Props
Published 2025-01-15 · Analyzed
6.5EPSS 0.006
CVE-2025-21088
WebApp crash via improper validation of proto style in attachments
Published 2025-01-15 · Analyzed
6.5EPSS 0.006
CVE-2023-1775
Unsanitized events sent over Websocket to regular users in a High Availability environment
Published 2023-03-31 · Modified
6.5EPSS 0.005
CVE-2024-22091
Excessive resource consumption due to lack to request path size limits
Published 2024-04-26 · Analyzed
6.5EPSS 0.005
CVE-2023-1777
Information disclosure in linked message previews
Published 2023-03-31 · Modified
6.5EPSS 0.005
CVE-2026-26233
Denial of Service via HTTP/2 single packet attack on login endpoint
Published 2026-03-25 · Analyzed
6.5EPSS 0.005
CVE-2024-28053
Resource Exhaustion via the Invitation Feature
Published 2024-03-15 · Analyzed
6.5EPSS 0.005
CVE-2023-5333
Denial of Service via multiple identical User IDs in /api/v4/users/ids
Published 2023-10-09 · Modified
6.5EPSS 0.005
CVE-2024-54682
Zipbomb DoS via Missing Slack Import Validation
Published 2024-12-16 · Analyzed
6.5EPSS 0.004
CVE-2026-7184
Mattermost Remote Cluster PATCH API Leaks Authentication Tokens
Published 2026-06-12 · Analyzed
6.5EPSS 0.004
CVE-2023-46701
Inaccessible Post Information Leak via Run Timeline IDOR
Published 2023-12-12 · Modified
6.5EPSS 0.004
CVE-2019-20844
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel.
Published 2020-06-19 · Modified
6.5EPSS 0.004
CVE-2025-20086
Insufficient Input Validation on Post Props
Published 2025-01-15 · Analyzed
6.5EPSS 0.004
CVE-2026-4054
SVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of service
Published 2026-05-15 · Analyzed
6.5EPSS 0.004
CVE-2026-14298
Denial of service via resource exhaustion in Mattermost
Published 2026-08-13 · Modified
6.5EPSS 0.004
CVE-2026-3114
Zip Bomb Denial of Service via Unrestricted Archive Decompression
Published 2026-03-26 · Analyzed
6.5EPSS 0.004
CVE-2026-10819
Mattermost Server Denial of Service via Animated GIF Emoji Upload
Published 2026-07-27 · Analyzed
6.5EPSS 0.004
CVE-2026-6850
Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost
Published 2026-07-13 · Analyzed
6.5EPSS 0.004
CVE-2026-6340
Memory Exhaustion via Malicious 7zip File Upload
Published 2026-05-18 · Analyzed
6.5EPSS 0.004
CVE-2026-5755
Denial of service via crafted TIFF file upload
Published 2026-05-22 · Analyzed
6.5EPSS 0.004
CVE-2026-10080
Boards plugin panics on WebSocket command with non-string field types
Published 2026-08-17 · Analyzed
6.5EPSS 0.004
CVE-2026-3117
Instance and webhook GitLab plugin commands were able to be run by non-admin users
Published 2026-05-18 · Analyzed
6.5EPSS 0.004
CVE-2026-6345
Prevent password disclosure and force reset during Slack import
Published 2026-05-18 · Analyzed
6.5EPSS 0.004
CVE-2024-23493
Team associated AD/LDAP Groups Leaked due to missing authorization
Published 2024-02-29 · Analyzed
6.5EPSS 0.004
CVE-2026-4915
Server panic via outgoing webhook responses
Published 2026-05-25 · Analyzed
6.5EPSS 0.004
CVE-2025-14822
DoS from quadratic complexity in model.ParseHashtags
Published 2026-01-16 · Analyzed
6.5EPSS 0.004
CVE-2026-9859
Mattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose boards to arbitrary channels
Published 2026-08-17 · Analyzed
6.5EPSS 0.003
CVE-2026-5163
Missing authorization check in AI message rewrite endpoint allows access to private thread content
Published 2026-05-18 · Analyzed
6.5EPSS 0.003
← Prev4 / 12Next →