← Back

Mattermost

mattermost

602 CVEs • 15 products

Products (15)

Click to collapse
Toggle

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mattermost
1Mattermost Server
Jun 17, 2026
Apr 25, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived t...Show more
When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team. Show less
1Mattermost
1Mattermost
Jun 17, 2026
Apr 20, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.
1Mattermost
1Mattermost Server
Jun 17, 2026
Apr 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings sect...Show more
Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config). Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Mar 31, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
1Mattermost
1Mattermost Server
Jun 17, 2026
Mar 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
1Mattermost
1Mattermost Server
Jun 17, 2026
Mar 31, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users...Show more
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients. Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Mar 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
1Mattermost
1Mattermost
Jun 17, 2026
Mar 22, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
1Mattermost
1Mattermost Server
Jun 17, 2026
Mar 15, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state param...Show more
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Feb 27, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in...Show more
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response. Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Feb 27, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in t...Show more
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response. Show less
1Mattermost
1Mattermost
Jun 17, 2026
Feb 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.
1Mattermost
1Mattermost
Jun 17, 2026
Feb 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.
1Mattermost
1Mattermost
Jun 17, 2026
Nov 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. 
1Mattermost
1Mattermost
Jun 17, 2026
Nov 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.
1Mattermost
1Mattermost
Jun 17, 2026
Nov 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.
1Mattermost
1Mattermost Server
Jun 17, 2026
Sep 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing...Show more
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Sep 9, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations,...Show more
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Jul 14, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of th...Show more
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Sla...Show more
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.Show less