Mattermost
626 known vulnerabilities
Top Products
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject
Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions
Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest t
Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with nul
Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playboo
Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint
Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to
Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the ch
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perf
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker w
Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to differe
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user cli
Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a me
Mattermost fails to check whether the “Allow users to view archived channels” setting is enabled during permalink prev
Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowi
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post.
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being i
Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a Use
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for ot
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enro
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowi
Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post w
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in loggin
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources
Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exp
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a s
Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a me
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really lo
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete ot
Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manag
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to
Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to re
Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged
Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user mana
Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, res
Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able t
Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a ne
Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server r
Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowi
Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdow
Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.
Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any us
Frequently Asked Questions
How many CVEs affect Mattermost?
Mattermost has 626 CVE records in our database, including 21 critical and 90 high severity vulnerabilities.
What are the most severe Mattermost vulnerabilities?
Mattermost has 21 critical severity (CVSS 9.0+) and 90 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Mattermost vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mattermost products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mattermost Vulnerabilities
CyberStrike scans your infrastructure for Mattermost vulnerabilities and provides real-time remediation guidance.
Get Started