Mattermost
626 known vulnerabilities
Top Products
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, by
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proce
An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRe
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a differe
An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent dur
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of s
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for
An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to mod
An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-mess
An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slas
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name w
An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a deni
An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing.
An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication creden
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A Syst
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A Syst
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denia
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastr
An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited
An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Upda
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via
An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address i
An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CS
An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermo
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted.
An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands.
An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a craf
An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cau
An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consum
An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown r
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sen
An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (cli
An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that ha
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information
An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video
An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAu
Frequently Asked Questions
How many CVEs affect Mattermost?
Mattermost has 626 CVE records in our database, including 21 critical and 90 high severity vulnerabilities.
What are the most severe Mattermost vulnerabilities?
Mattermost has 21 critical severity (CVSS 9.0+) and 90 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Mattermost vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mattermost products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mattermost Vulnerabilities
CyberStrike scans your infrastructure for Mattermost vulnerabilities and provides real-time remediation guidance.
Get Started