VendorsMattermostmattermost_serverall versions
Vulnerabilities

Mattermost Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2025-55073
MS Teams plugin OAuth allows editing arbitrary posts
Published 2025-11-14 · Analyzed
5.4EPSS 0.002
CVE-2026-0999
Authentication bypass via userID login when email and username login are disabled
Published 2026-02-16 · Analyzed
5.4EPSS 0.002
CVE-2020-14452
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.
Published 2020-06-19 · Modified
5.3EPSS 0.013
CVE-2016-11067
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
Published 2020-06-19 · Modified
5.3EPSS 0.011
CVE-2017-18898
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang.
Published 2020-06-19 · Modified
5.3EPSS 0.011
CVE-2017-18873
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post.
Published 2020-06-19 · Modified
5.3EPSS 0.011
CVE-2018-21259
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.
Published 2020-06-19 · Modified
5.3EPSS 0.011
CVE-2017-18899
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
Published 2020-06-19 · Modified
5.3EPSS 0.011
CVE-2017-18887
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2017-18895
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via a REST API version 4 endpoint.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2017-18901
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON document.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2017-18902
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2016-11068
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2016-11075
An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2020-14457
An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka MMSA-2020-0012.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2019-20866
An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address in an IP packet header, for obtaining IP address information was mishandled.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2019-20877
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2016-11076
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2016-11062
An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2018-21257
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2017-18914
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2019-20847
An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any channel.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2019-20867
An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2019-20869
An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2019-20884
An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2017-18916
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2017-18896
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2017-18905
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2019-20889
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2017-18919
An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2019-20875
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2019-20882
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2023-6459
Public endpoint /metrics of Calls plugin reveals channel IDs
Published 2023-12-06 · Modified
5.3EPSS 0.005
CVE-2025-22445
Misleading UI for undefined admin console settings in Calls causes security confusion
Published 2025-01-09 · Analyzed
5.3EPSS 0.003
CVE-2023-5331
File Information Leak via IDOR in file_id in Draft Posts
Published 2023-10-09 · Modified
5.3EPSS 0.003
CVE-2025-3913
Team Privacy Settings Authorization Bypass in Mattermost Server
Published 2025-05-29 · Analyzed
5.3EPSS 0.003
CVE-2026-6046
Plugin bot username conflict allows user account to be used as bot identity in Mattermost Server
Published 2026-06-12 · Analyzed
5.3EPSS 0.003
CVE-2025-0503
Leaked User IDs and Metadata of Deleted DMs
Published 2025-02-14 · Analyzed
5.3EPSS 0.003
CVE-2026-6333
SSRF via Host Header Spoofing in Custom Slash Commands
Published 2026-05-18 · Analyzed
5.0EPSS 0.002
CVE-2017-18876
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
Published 2020-06-19 · Modified
4.9EPSS 0.009
← Prev7 / 12Next →