VendorsMattermostmattermost_serverall versions
Vulnerabilities

Mattermost Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2024-1402
Denial of service in mattermost mobile apps and server via emoji reactions
Published 2024-02-09 · Modified
4.3EPSS 0.005
CVE-2024-1953
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.
Published 2024-02-29 · Analyzed
4.3EPSS 0.005
CVE-2023-2281
Archiving a team broadcasts unsanitized data over WebSockets
Published 2023-04-25 · Modified
4.3EPSS 0.005
CVE-2023-48732
Keywords that trigger mentions are leaked to other users
Published 2024-01-02 · Modified
4.3EPSS 0.005
CVE-2024-32046
Detailed error discloses full file path with dev mode off
Published 2024-04-26 · Analyzed
4.3EPSS 0.005
CVE-2024-2446
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentions processed per message, allowing an authenticated attacker to crash the client applications of other users via large, crafted messages.
Published 2024-03-15 · Analyzed
4.3EPSS 0.004
CVE-2026-4646
Insufficient input validation in GitHub plugin API causes denial of service
Published 2026-05-22 · Analyzed
4.3EPSS 0.004
CVE-2023-6727
Leak Inaccessible Playbook Information via Channel Action IDOR
Published 2023-12-12 · Modified
4.3EPSS 0.004
CVE-2023-3577
Limited blind SSRF to localhost/intranet in interactive dialog implementation
Published 2023-07-17 · Modified
4.3EPSS 0.004
CVE-2023-49874
IDOR when updating the tasks of a private playbook run
Published 2023-12-12 · Modified
4.3EPSS 0.004
CVE-2026-25783
Denial of service via malformed User-Agent header in getBrowserVersion
Published 2026-03-16 · Analyzed
4.3EPSS 0.004
CVE-2026-26246
Memory Exhaustion via Malformed PSD File Upload
Published 2026-03-16 · Analyzed
4.3EPSS 0.004
CVE-2026-25780
Memory Exhaustion via Malformed DOC File Upload
Published 2026-03-16 · Analyzed
4.3EPSS 0.004
CVE-2024-1952
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.
Published 2024-02-29 · Analyzed
4.3EPSS 0.004
CVE-2026-10600
Denial of service via unbounded document content extraction in Mattermost Server
Published 2026-07-27 · Analyzed
4.3EPSS 0.004
CVE-2026-4265
Guest user can upload files without permission across teams
Published 2026-03-16 · Analyzed
4.3EPSS 0.004
CVE-2024-1942
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.
Published 2024-02-29 · Analyzed
4.3EPSS 0.004
CVE-2023-47858
Details of archived public channels are leaked to members of another team
Published 2024-01-02 · Modified
4.3EPSS 0.004
CVE-2023-3582
Lack of channel membership check when linking a board to a channel
Published 2023-07-17 · Modified
4.3EPSS 0.004
CVE-2023-3614
Denial of Service via specially crafted gif image
Published 2023-07-17 · Modified
4.3EPSS 0.004
CVE-2024-39839
Remote username set to an arbitrary string by remote user
Published 2024-08-01 · Analyzed
4.3EPSS 0.003
CVE-2026-9162
Global session revocation does not invalidate active WebSocket connections
Published 2026-06-22 · Analyzed
4.3EPSS 0.003
CVE-2024-1887
Public channel post content accessible without membership when compliance export is enabled
Published 2024-02-29 · Analyzed
4.3EPSS 0.003
CVE-2024-1888
Existing server guests invited to the team by members without "invite_guest" permission
Published 2024-02-29 · Analyzed
4.3EPSS 0.003
CVE-2026-16045
Delegated OAuth tokens could revoke unrelated OAuth application authorizations
Published 2026-08-17 · Analyzed
4.3EPSS 0.003
CVE-2025-10545
Guest user can add unauthorized team users to private channels
Published 2025-10-16 · Analyzed
4.3EPSS 0.003
CVE-2023-50333
Lack of restriction to manage group names for freshly demoted guests
Published 2024-01-02 · Modified
4.3EPSS 0.003
CVE-2024-23488
Files of archived channels accessible with the “Allow users to view archived channels” option disabled
Published 2024-02-29 · Analyzed
4.3EPSS 0.003
CVE-2024-24776
Incorrect Authorization leads to Channel Member Count Leak
Published 2024-02-09 · Modified
4.3EPSS 0.003
CVE-2025-41443
Guest user can discover active public channels
Published 2025-10-16 · Modified
4.3EPSS 0.003
CVE-2026-3433
Mattermost fails to scope role_updated websocket events to authorized team and channel members
Published 2026-06-12 · Analyzed
4.3EPSS 0.003
CVE-2025-2527
Improper access control to group information
Published 2025-05-15 · Analyzed
4.3EPSS 0.003
CVE-2026-2578
Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read Posts
Published 2026-03-16 · Analyzed
4.3EPSS 0.003
CVE-2026-3636
Sanitize team member data returned by API
Published 2026-05-22 · Analyzed
4.3EPSS 0.003
CVE-2024-34029
AD/LDAP Group Members Leak
Published 2024-05-26 · Analyzed
4.3EPSS 0.003
CVE-2024-52032
Private channel names leaking when Elasticsearch is enabled
Published 2024-11-09 · Analyzed
4.3EPSS 0.003
CVE-2024-10241
Private channel names leaked with Ctrl+K when ElasticSearch is enabled
Published 2024-10-29 · Analyzed
4.3EPSS 0.003
CVE-2025-24526
Channel export permitted on archived channel when viewing archived channels is disabled
Published 2025-02-24 · Analyzed
4.3EPSS 0.003
CVE-2025-3228
Unauthorized Guest user access to Playbook
Published 2025-06-20 · Analyzed
4.3EPSS 0.003
CVE-2024-42000
Unauthorized Access to view channels' details
Published 2024-11-09 · Analyzed
4.3EPSS 0.003
← Prev9 / 12Next →