VendorsMattermostmattermost_serverany version
Vulnerabilities

Mattermost Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2025-6226
IDOR in CreatePost API allows for timeboxed message disclosure
Published 2025-07-18 · Analyzed
6.5EPSS 0.003
CVE-2026-21388
Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint
Published 2026-04-09 · Analyzed
6.5EPSS 0.003
CVE-2025-30179
MFA Enforcement Bypass in Search APIs
Published 2025-03-21 · Analyzed
6.5EPSS 0.003
CVE-2026-9571
Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost
Published 2026-07-13 · Analyzed
6.5EPSS 0.003
CVE-2026-10106
Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost
Published 2026-07-13 · Analyzed
6.5EPSS 0.003
CVE-2025-12689
DoS in Calls plugin via malformed UTF-8 in WebSocket request
Published 2025-12-17 · Analyzed
6.5EPSS 0.003
CVE-2026-4635
Persistent notification timing attack causing server denial of service
Published 2026-05-22 · Analyzed
6.5EPSS 0.003
CVE-2025-31363
Data exfiltration via AI plugin Jira tool
Published 2025-04-16 · Analyzed
6.5EPSS 0.003
CVE-2025-9081
IDOR in board file download allows any user to download any file by UUID
Published 2025-09-19 · Analyzed
6.5EPSS 0.003
CVE-2025-9076
Mattermost Server exposes sensitive user credentials during shared channel membership synchronization
Published 2025-09-15 · Analyzed
6.5EPSS 0.003
CVE-2026-2325
Improper Input Validation in MS Teams Meetings API Handler
Published 2026-05-18 · Analyzed
6.5EPSS 0.002
CVE-2024-2447
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.
Published 2024-04-05 · Analyzed
6.5EPSS 0.002
CVE-2026-3590
Race Condition in Guest Magic Link Authentication Allows Token Reuse
Published 2026-04-15 · Analyzed
6.5EPSS 0.002
CVE-2026-4339
SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server
Published 2026-06-26 · Analyzed
6.5EPSS 0.001
CVE-2026-6673
Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install
Published 2026-06-22 · Analyzed
6.4EPSS 0.003
CVE-2026-6062
IDOR in Jira plugin subscription edit endpoint
Published 2026-06-22 · Analyzed
6.4EPSS 0.002
CVE-2026-16048
Channel member roles accept out-of-scope roles
Published 2026-08-17 · Analyzed
6.3EPSS 0.003
CVE-2026-10527
Boards plugin retains Board Admin rights for users demoted to System Guest
Published 2026-08-17 · Analyzed
6.3EPSS 0.003
CVE-2024-31859
Member promoted to channel admin via playbooks run linking to channel
Published 2024-05-26 · Analyzed
6.3EPSS 0.002
CVE-2017-18897
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18891
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18879
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2016-11079
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2016-11071
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2016-11082
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2016-11083
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18892
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18893
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2016-11073
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2016-11063
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18904
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18907
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18877
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18913
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18880
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18881
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18882
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2017-18921
An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.
Published 2020-06-19 · Modified
6.1EPSS 0.007
CVE-2023-1421
Reflected XSS in OAuth flow completion endpoints
Published 2023-03-15 · Modified
6.1EPSS 0.004
CVE-2016-11084
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
Published 2020-06-19 · Modified
6.1EPSS 0.003
← Prev5 / 12Next →