VendorsMattermostmattermost_serverall versions
Vulnerabilities

Mattermost Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2017-18875
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
Published 2020-06-19 · Modified
4.9EPSS 0.007
CVE-2017-18918
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.
Published 2020-06-19 · Modified
4.9EPSS 0.005
CVE-2026-3116
Improper Input Validation in Zoom Plugin Webhook Handler
Published 2026-03-26 · Analyzed
4.9EPSS 0.004
CVE-2026-9708
Incoming webhook user attribution via unvalidated webhook owner
Published 2026-07-13 · Analyzed
4.9EPSS 0.004
CVE-2025-8402
Nil pointer dereference in bulk import crashes server
Published 2025-08-21 · Analyzed
4.9EPSS 0.003
CVE-2025-11794
Password hash and MFA secret returned in user email verification endpoint
Published 2025-11-14 · Analyzed
4.9EPSS 0.003
CVE-2025-32093
Syatem admin profile modification by delegated granular administration role
Published 2025-04-14 · Analyzed
4.9EPSS 0.002
CVE-2024-48872
Bypass of "Max failed attempts" restriction via race condition
Published 2024-12-16 · Analyzed
4.8EPSS 0.003
CVE-2026-3495
Unescaped variables during error page composition
Published 2026-05-18 · Analyzed
4.8EPSS 0.002
CVE-2024-36250
MFA Code Replay
Published 2024-11-09 · Analyzed
4.8EPSS 0.002
CVE-2024-29221
Invite ID available to team admins even without the "Add Members" permission
Published 2024-04-05 · Analyzed
4.7EPSS 0.003
CVE-2026-27659
CSRF vulnerability in UpdateAccessControlPolicyActiveStatus endpoint
Published 2026-03-25 · Analyzed
4.6EPSS 0.002
CVE-2024-12247
Improper propagation of permission scheme updates across cluster nodes
Published 2024-12-05 · Analyzed
4.6EPSS 0.002
CVE-2024-46872
Client-Side Path Traversal Leading to CSRF in Playbooks
Published 2024-10-29 · Analyzed
4.6EPSS 0.002
CVE-2017-18878
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
Published 2020-06-19 · Modified
4.3EPSS 0.008
CVE-2017-18890
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.
Published 2020-06-19 · Modified
4.3EPSS 0.008
CVE-2019-20890
An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
Published 2020-06-19 · Modified
4.3EPSS 0.008
CVE-2025-6465
Path traversal in image upload with preview overwrite
Published 2025-08-21 · Analyzed
4.3EPSS 0.008
CVE-2016-11081
An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser.
Published 2020-06-19 · Modified
4.3EPSS 0.008
CVE-2019-20878
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.
Published 2020-06-19 · Modified
4.3EPSS 0.007
CVE-2018-21249
An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing.
Published 2020-06-19 · Modified
4.3EPSS 0.007
CVE-2019-20870
An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited flag after changing a post's file ID.
Published 2020-06-19 · Modified
4.3EPSS 0.007
CVE-2017-18889
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.
Published 2020-06-19 · Modified
4.3EPSS 0.007
CVE-2016-11080
An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details.
Published 2020-06-19 · Modified
4.3EPSS 0.007
CVE-2019-20887
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
Published 2020-06-19 · Modified
4.3EPSS 0.007
CVE-2022-1332
Restricted custom admin role can bypass the restrictions and view the server logs and server config.json file contents
Published 2022-04-13 · Modified
4.3EPSS 0.007
CVE-2019-20883
An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2016-11065
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2017-18870
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2018-21254
An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2018-21256
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2018-21252
An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2017-18910
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2018-21255
An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2018-21261
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2018-21253
An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2019-20879
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2017-18872
An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
Published 2020-06-19 · Modified
4.3EPSS 0.006
CVE-2024-4182
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
Published 2024-04-26 · Analyzed
4.3EPSS 0.006
CVE-2023-3585
channel DoS by sharing a boards link
Published 2023-07-17 · Modified
4.3EPSS 0.005
← Prev8 / 12Next →