Mattermost
626 known vulnerabilities
Top Products
An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a
An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel
An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the upd
An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-contr
An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, a
An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application
An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, whi
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-001
An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local St
An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers to cause a denial of
An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to thir
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a
An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of
An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.
An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any ch
An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.
An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory con
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a d
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permission
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur
Frequently Asked Questions
How many CVEs affect Mattermost?
Mattermost has 626 CVE records in our database, including 21 critical and 90 high severity vulnerabilities.
What are the most severe Mattermost vulnerabilities?
Mattermost has 21 critical severity (CVSS 9.0+) and 90 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Mattermost vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mattermost products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mattermost Vulnerabilities
CyberStrike scans your infrastructure for Mattermost vulnerabilities and provides real-time remediation guidance.
Get Started