VendorsMattermostmattermost_serverany version
Vulnerabilities

Mattermost Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2026-27656
Account Takeover via Substring Matching in OpenID Connect Authentication
Published 2026-03-25 · Analyzed
6.1EPSS 0.003
CVE-2024-2445
Reflected XSS in Mattermost Jira plugin
Published 2024-03-15 · Analyzed
6.1EPSS 0.003
CVE-2023-7113
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
Published 2023-12-29 · Modified
6.1EPSS 0.003
CVE-2025-9084
Open redirect in OAuth login
Published 2025-09-15 · Analyzed
6.1EPSS 0.002
CVE-2025-62690
Open redirect in error page when link opened in new tab
Published 2025-12-17 · Analyzed
6.1EPSS 0.001
CVE-2024-42497
Insufficient permissions checks on teams
Published 2024-08-22 · Analyzed
6.0EPSS 0.003
CVE-2025-27936
Webhook Secret Exposure via Timing attack in MSteams plugin
Published 2025-04-16 · Analyzed
5.9EPSS 0.003
CVE-2024-32045
Playbook run link to private channel grants channel access
Published 2024-05-26 · Analyzed
5.9EPSS 0.002
CVE-2022-1385
Invitation Email is resent as a Reminder after invalidating pending email invites
Published 2022-04-19 · Modified
5.8EPSS 0.008
CVE-2021-37862
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.
Published 2021-12-17 · Modified
5.8EPSS 0.007
CVE-2025-31947
Repeated LDAP login failures can lock an LDAP account
Published 2025-05-15 · Analyzed
5.8EPSS 0.003
CVE-2021-37863
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
Published 2021-12-17 · Modified
5.7EPSS 0.008
CVE-2025-13821
User profile update exposes password hash and MFA secrets
Published 2026-02-16 · Analyzed
5.7EPSS 0.002
CVE-2024-36255
Post actions can run playbook checklist task commands
Published 2024-05-26 · Analyzed
5.7EPSS 0.002
CVE-2026-2456
Denial of Service via Unbounded Memory Allocation in Integration Actions
Published 2026-03-16 · Analyzed
5.7EPSS 0.002
CVE-2022-2366
Incorrect defaults can cause attackers to bypass rate limitations
Published 2022-07-11 · Modified
5.6EPSS 0.006
CVE-2019-20860
An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.
Published 2020-06-19 · Modified
5.5EPSS 0.009
CVE-2019-20876
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
Published 2020-06-19 · Modified
5.5EPSS 0.008
CVE-2026-7521
SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory
Published 2026-07-28 · Analyzed
5.5EPSS 0.004
CVE-2019-20872
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
Published 2020-06-19 · Modified
5.5EPSS 0.003
CVE-2026-3113
mmctl export download command doesn’t restrict permissions to created file to file owner
Published 2026-03-26 · Analyzed
5.5EPSS 0.001
CVE-2016-11070
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
Published 2020-06-19 · Modified
5.4EPSS 0.006
CVE-2023-1774
Unauthorized email invite to a private channel
Published 2023-03-31 · Modified
5.4EPSS 0.003
CVE-2023-6547
Playbooks access/modification by removed team member
Published 2023-12-12 · Modified
5.4EPSS 0.003
CVE-2025-41410
Slack import bypasses email verification for team access controls
Published 2025-10-16 · Analyzed
5.4EPSS 0.003
CVE-2026-10085
Ordinary group/direct message member can enable group_constrained and remove all channel participants
Published 2026-07-13 · Analyzed
5.4EPSS 0.003
CVE-2026-5139
GitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration
Published 2026-06-22 · Analyzed
5.4EPSS 0.003
CVE-2026-16044
Insufficient validation of guest board admin privileges on archive import
Published 2026-08-17 · Analyzed
5.4EPSS 0.003
CVE-2024-39837
Malicious remote can create arbitrary channels
Published 2024-08-01 · Analyzed
5.4EPSS 0.003
CVE-2023-3586
Disabling publicly-shared boards does not disable existing publicly available board links
Published 2023-07-17 · Modified
5.4EPSS 0.003
CVE-2026-9597
Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
Published 2026-07-13 · Analyzed
5.4EPSS 0.002
CVE-2026-4274
Insufficient authorization in shared channel membership sync grants team-level access instead of channel-level access
Published 2026-03-26 · Analyzed
5.4EPSS 0.002
CVE-2026-28735
GitHub OAuth Scope Validation
Published 2026-05-22 · Analyzed
5.4EPSS 0.002
CVE-2025-2475
Unauthorized Bot Login Using Credentials
Published 2025-04-14 · Analyzed
5.4EPSS 0.002
CVE-2024-42406
Unauthorized access on archived channels
Published 2024-09-26 · Analyzed
5.4EPSS 0.002
CVE-2025-3230
Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server
Published 2025-05-30 · Analyzed
5.4EPSS 0.002
CVE-2024-45843
Weak SSRF Filtering
Published 2024-09-26 · Analyzed
5.4EPSS 0.002
CVE-2025-27933
Unauthorized Private-to-Public Channel Conversion
Published 2025-03-21 · Analyzed
5.4EPSS 0.002
CVE-2025-46702
Mattermost Playbooks allows privilege escalation through improper access control in playbook run participant management
Published 2025-06-30 · Analyzed
5.4EPSS 0.002
CVE-2025-47871
Mattermost Playbooks exposes private channel metadata to unauthorized users via run metadata API
Published 2025-06-30 · Analyzed
5.4EPSS 0.002
← Prev6 / 12Next →