Mattermost
626 known vulnerabilities
Top Products
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the syste
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, wh
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an atta
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allo
Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, w
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of
Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while draft
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows auth
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated at
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers
Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.
Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes o
An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.
An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.
An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitation
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker mi
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An att
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a b
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web br
An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view a
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive informati
An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about tea
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishand
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to ha
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal informati
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up me
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
Frequently Asked Questions
How many CVEs affect Mattermost?
Mattermost has 626 CVE records in our database, including 21 critical and 90 high severity vulnerabilities.
What are the most severe Mattermost vulnerabilities?
Mattermost has 21 critical severity (CVSS 9.0+) and 90 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Mattermost vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mattermost products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mattermost Vulnerabilities
CyberStrike scans your infrastructure for Mattermost vulnerabilities and provides real-time remediation guidance.
Get Started