Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Mattermost

626 known vulnerabilities

21
CRITICAL
90
HIGH
384
MEDIUM
128
LOW

Top Products

mattermost server 467 mattermost 77 mattermost desktop 31 mattermost mobile 21 confluence 14 legal hold 2 focalboard 2 ms teams 2 zoom 2 playbooks 2
623 CVEs · Page 4/13
9.9
CVE-2025-12419

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validat

3.0
CVE-2025-55074

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which

4.9
CVE-2025-11794

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows sy

5.4
CVE-2025-55073

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between

6.5
CVE-2025-55070

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticate

3.1
CVE-2025-41436

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regu

4.3
CVE-2025-11776

Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to disc

6.1
CVE-2025-59480

Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, whic

3.1
CVE-2025-11777

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the A

6.1
CVE-2025-55035

Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a se

8.1
CVE-2025-58075

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo

8.1
CVE-2025-58073

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo

3.1
CVE-2025-54499

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comp

5.4
CVE-2025-41410

Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Sl

3.1
CVE-2025-10545

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding c

4.3
CVE-2025-41443

Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessin

3.5
CVE-2025-58084

Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing

3.1
CVE-2025-9081

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authe

8.0
CVE-2025-9079

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to

3.1
CVE-2025-9084

Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to

7.6
CVE-2025-9072

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, a

4.3
CVE-2025-9078

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to

6.5
CVE-2025-9076

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronizat

4.9
CVE-2025-8402

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to

4.3
CVE-2025-6465

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names

6.8
CVE-2025-8023

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path trave

3.8
CVE-2025-53971

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role mod

3.5
CVE-2025-49810

Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thre

6.8
CVE-2025-49222

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to

4.3
CVE-2025-47870

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team in

3.5
CVE-2025-47700

Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows

6.8
CVE-2025-36530

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate fi

4.0
CVE-2025-8285

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers

7.5
CVE-2025-54525

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the

7.2
CVE-2025-54478

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which

5.9
CVE-2025-54463

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the

5.0
CVE-2025-54458

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows a

4.0
CVE-2025-53910

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers

3.7
CVE-2025-53857

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers

5.9
CVE-2025-53514

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the

7.5
CVE-2025-52931

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the

3.7
CVE-2025-49221

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which

6.4
CVE-2025-48731

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows a

7.2
CVE-2025-44004

Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance whic

4.0
CVE-2025-44001

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers

2.2
CVE-2025-6227

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which al

6.8
CVE-2025-6233

Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths

6.5
CVE-2025-6226

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization

4.3
CVE-2025-47871

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr

5.4
CVE-2025-46702

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr

Frequently Asked Questions

How many CVEs affect Mattermost?

Mattermost has 626 CVE records in our database, including 21 critical and 90 high severity vulnerabilities.

What are the most severe Mattermost vulnerabilities?

Mattermost has 21 critical severity (CVSS 9.0+) and 90 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Mattermost vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mattermost products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Mattermost Vulnerabilities

CyberStrike scans your infrastructure for Mattermost vulnerabilities and provides real-time remediation guidance.

Get Started