VendorsMattermostmattermost_serverany version
Vulnerabilities

Mattermost Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2025-25279
Arbitrary file read in Mattermost Boards via import & export board archive
Published 2025-02-24 · Analyzed
9.9EPSS 0.240
CVE-2025-4981
Path Traversal Leading to RCE by Any Authenticated Mattermost User
Published 2025-06-20 · Analyzed
9.9EPSS 0.008
CVE-2025-20051
Arbitrary file read via block duplication in Mattermost Boards
Published 2025-02-24 · Analyzed
9.9EPSS 0.006
CVE-2025-12419
Account takeover on OAuth/OpenID-enabled servers
Published 2025-11-27 · Analyzed
9.9EPSS 0.003
CVE-2025-12421
Account Takeover via Code Exchange Endpoint
Published 2025-11-27 · Analyzed
9.9EPSS 0.003
CVE-2026-4858
Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.
Published 2026-05-21 · Analyzed
9.9EPSS 0.003
CVE-2017-18912
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.
Published 2020-06-19 · Modified
9.8EPSS 0.014
CVE-2017-18900
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.
Published 2020-06-19 · Modified
9.8EPSS 0.013
CVE-2017-18920
An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.
Published 2020-06-19 · Modified
9.8EPSS 0.012
CVE-2018-21251
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.
Published 2020-06-19 · Modified
9.8EPSS 0.012
CVE-2017-18885
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
Published 2020-06-19 · Modified
9.8EPSS 0.012
CVE-2017-18908
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.
Published 2020-06-19 · Modified
9.8EPSS 0.012
CVE-2016-11074
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
Published 2020-06-19 · Modified
9.8EPSS 0.012
CVE-2017-18915
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.
Published 2020-06-19 · Modified
9.8EPSS 0.012
CVE-2017-18888
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
Published 2020-06-19 · Modified
9.8EPSS 0.011
CVE-2023-6458
Client side path traversal due to lack of route parameters validation
Published 2023-12-06 · Modified
9.8EPSS 0.006
CVE-2025-24490
SQL Injection in Mattermost Boards via board category ID reordering
Published 2025-02-24 · Analyzed
9.6EPSS 0.004
CVE-2017-18883
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
Published 2020-06-19 · Modified
9.1EPSS 0.011
CVE-2017-18911
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
Published 2020-06-19 · Modified
9.1EPSS 0.007
CVE-2018-21264
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.
Published 2020-06-19 · Modified
8.8EPSS 0.011
CVE-2017-18886
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
Published 2020-06-19 · Modified
8.8EPSS 0.009
CVE-2018-21263
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.
Published 2020-06-19 · Modified
8.8EPSS 0.009
CVE-2022-1384
Authorized users are allowed to install old plugin versions from the Marketplace
Published 2022-04-19 · Modified
8.8EPSS 0.007
CVE-2024-2450
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.
Published 2024-03-15 · Analyzed
8.8EPSS 0.006
CVE-2019-20865
An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.
Published 2020-06-19 · Modified
8.8EPSS 0.005
CVE-2023-2515
Privilege escalation to system admin via personal access tokens
Published 2023-05-12 · Modified
8.8EPSS 0.005
CVE-2019-20841
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.
Published 2020-06-19 · Modified
8.8EPSS 0.004
CVE-2017-18903
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
Published 2020-06-19 · Modified
8.8EPSS 0.004
CVE-2025-25274
Unauthorized Command Execution in Archived Channels
Published 2025-03-21 · Analyzed
8.8EPSS 0.004
CVE-2025-25068
Bypassing MFA Enforcement on Plugin Endpoints
Published 2025-03-21 · Analyzed
8.8EPSS 0.003
CVE-2023-45316
Reflected client side path traversal leading to CSRF in Playbooks
Published 2023-12-12 · Modified
8.8EPSS 0.003
CVE-2026-7387
Mattermost group syncable endpoints allow privilege escalation via scheme_admin
Published 2026-06-12 · Analyzed
8.8EPSS 0.003
CVE-2026-3108
Terminal Escape Injection in mmctl Report Posts Command
Published 2026-03-26 · Analyzed
8.8EPSS 0.003
CVE-2025-1412
Session Persistence After User-to-Bot Conversion
Published 2025-02-24 · Analyzed
8.8EPSS 0.003
CVE-2026-6346
Sensitive credentials exposed in plaintext in Mattermost support packets
Published 2026-05-18 · Analyzed
8.7EPSS 0.003
CVE-2026-2454
DoS in Calls plugin via malformed msgpack in websocket request.
Published 2026-03-16 · Analyzed
8.6EPSS 0.003
CVE-2026-9816
Insufficient server-side validation of board member role fields permits privilege escalation
Published 2026-08-17 · Analyzed
8.3EPSS 0.003
CVE-2025-14273
Mattermost Jira plugin user spoofing enables Jira request forgery.
Published 2025-12-22 · Analyzed
8.3EPSS 0.003
CVE-2023-4478
Parameter tampering in the registration resulting in blocked accounts to be created
Published 2023-08-25 · Modified
8.2EPSS 0.005
CVE-2024-11599
Domain Restriction Bypass on Registration
Published 2024-11-28 · Analyzed
8.2EPSS 0.005
1 / 12Next →