Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Mattermost

626 known vulnerabilities

21
CRITICAL
90
HIGH
384
MEDIUM
128
LOW

Top Products

mattermost server 467 mattermost 77 mattermost desktop 31 mattermost mobile 21 confluence 14 legal hold 2 focalboard 2 ms teams 2 zoom 2 playbooks 2
623 CVEs · Page 8/13
7.1
CVE-2023-7114

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks

3.7
CVE-2023-7113

Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject

3.1
CVE-2023-6727

Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access

3.7
CVE-2023-6547

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions

4.3
CVE-2023-49874

Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest t

4.3
CVE-2023-49809

Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with nul

4.3
CVE-2023-49607

Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playboo

6.5
CVE-2023-46701

Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint

4.3
CVE-2023-45847

Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to

7.3
CVE-2023-45316

Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a

5.3
CVE-2023-6459

Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the ch

7.1
CVE-2023-6458

Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perf

4.3
CVE-2023-6202

Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker w

4.3
CVE-2023-48369

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to differe

4.3
CVE-2023-48268

Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards

4.3
CVE-2023-47168

Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user cli

4.3
CVE-2023-45223

Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a me

4.3
CVE-2023-43754

Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink prev

4.3
CVE-2023-40703

Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a

3.1
CVE-2023-35075

Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowi

4.3
CVE-2023-47865

Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post.

5.3
CVE-2023-5969

Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially

4.9
CVE-2023-5968

Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being i

4.3
CVE-2023-5967

Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a Use

2.9
CVE-2023-5920

Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for ot

3.1
CVE-2023-5876

Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enro

3.7
CVE-2023-5875

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowi

4.3
CVE-2023-5522

Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post w

4.7
CVE-2023-5339

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in loggin

4.3
CVE-2023-5333

Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources

4.3
CVE-2023-5331

Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exp

4.3
CVE-2023-5330

Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a s

4.3
CVE-2023-5160

Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a me

6.5
CVE-2023-5196

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really lo

6.5
CVE-2023-5195

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete ot

2.7
CVE-2023-5194

Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manag

4.9
CVE-2023-5193

Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to

3.8
CVE-2023-5159

Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user

4.3
CVE-2023-4478

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to re

4.5
CVE-2023-4108

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

6.7
CVE-2023-4107

Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user mana

6.3
CVE-2023-4106

Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, res

3.1
CVE-2023-4105

Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able t

8.1
CVE-2023-3615

Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a ne

4.3
CVE-2023-3614

Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server r

3.5
CVE-2023-3613

Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowi

4.3
CVE-2023-3593

Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdow

4.8
CVE-2023-3591

Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.

3.1
CVE-2023-3590

Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.

2.7
CVE-2023-3587

Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any us

Frequently Asked Questions

How many CVEs affect Mattermost?

Mattermost has 626 CVE records in our database, including 21 critical and 90 high severity vulnerabilities.

What are the most severe Mattermost vulnerabilities?

Mattermost has 21 critical severity (CVSS 9.0+) and 90 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Mattermost vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mattermost products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Mattermost Vulnerabilities

CyberStrike scans your infrastructure for Mattermost vulnerabilities and provides real-time remediation guidance.

Get Started