📦 Mattermost Server

by Mattermost

🔍 What is Mattermost Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-12421

CRITICAL CVSS 9.9 Nov 27, 2025

This vulnerability allows authenticated Mattermost users to perform account takeover by exploiting a flaw in the SSO code exchange process. Attackers can switch authentication methods using a speciall...

CVE-2025-12419

CRITICAL CVSS 9.9 Nov 27, 2025

This vulnerability allows authenticated attackers with team creation privileges to take over user accounts in Mattermost by manipulating OAuth state tokens during OpenID Connect authentication. It aff...

CVE-2025-4981

CRITICAL CVSS 9.9 Jun 20, 2025

This vulnerability allows authenticated Mattermost users to write files to arbitrary locations on the filesystem by uploading archives containing path traversal sequences in filenames. This can lead t...

CVE-2025-20051

CRITICAL CVSS 9.9 Feb 24, 2025

This vulnerability in Mattermost Boards allows authenticated users to read arbitrary files on the server by duplicating specially crafted blocks. It affects Mattermost instances running vulnerable ver...

CVE-2025-25279

CRITICAL CVSS 9.9 Feb 24, 2025

This vulnerability in Mattermost Boards allows attackers to read arbitrary files on the server by importing specially crafted board archives. It affects Mattermost instances running vulnerable version...

CVE-2025-14273

HIGH CVSS 7.2 Dec 22, 2025

This vulnerability allows unauthenticated attackers to bypass authentication in Mattermost's Jira plugin and make authenticated requests to Jira servers. Attackers can spoof user IDs and inject arbitr...

CVE-2025-58075

HIGH CVSS 8.1 Oct 16, 2025

This vulnerability allows attackers to join any Mattermost team without proper authorization by manipulating RelayState parameters. Attackers can bypass team invitation restrictions and gain unauthori...

CVE-2025-9079

HIGH CVSS 8.0 Sep 19, 2025

This vulnerability allows admin users in Mattermost to execute arbitrary code by uploading malicious plugins to the prepackaged plugins directory. The system fails to validate import directory path co...

CVE-2025-9072

HIGH CVSS 7.6 Sep 15, 2025

Mattermost SAML authentication redirect vulnerability allows attackers to steal user session cookies via malicious links. When users authenticate through SAML, the system fails to validate redirect UR...

CVE-2025-25068

HIGH CVSS 7.5 Mar 21, 2025

Mattermost fails to enforce multi-factor authentication (MFA) on plugin endpoints, allowing authenticated attackers to bypass MFA protections via API requests to plugin-specific routes. This affects M...

CVE-2024-11599

HIGH CVSS 8.2 Nov 28, 2024

This vulnerability allows unauthenticated attackers to bypass email domain restrictions in Mattermost by submitting specially crafted email addresses during registration. Affected organizations are th...

CVE-2024-2450

HIGH CVSS 8.8 Mar 15, 2024

This vulnerability allows authenticated attackers to take over other user accounts in Mattermost by exploiting a flaw in authentication switching from email to SAML. Attackers can craft malicious swit...

CVE-2023-6458

HIGH CVSS 7.1 Dec 6, 2023

Mattermost web applications fail to properly validate route parameters in the team/channel URL path, allowing attackers to perform client-side path traversal. This vulnerability affects Mattermost ins...

CVE-2023-1776

HIGH CVSS 7.3 Mar 31, 2023

This vulnerability allows attackers to upload malicious SVG files to Mattermost Boards and share them via direct links. When users view these SVG files, cross-site scripting (XSS) attacks can execute ...

CVE-2025-14350

MEDIUM CVSS 4.3 Feb 16, 2026

This vulnerability allows authenticated Mattermost users to discover the existence of teams and their URL names by posting channel shortlinks and observing API responses. It affects Mattermost instanc...

CVE-2025-13821

MEDIUM CVSS 5.7 Feb 16, 2026

This vulnerability allows authenticated Mattermost users to exfiltrate sensitive data including password hashes and MFA secrets through WebSocket messages. The flaw occurs when users update their prof...

CVE-2026-0999

MEDIUM CVSS 5.4 Feb 16, 2026

This vulnerability allows authenticated users to bypass SSO-only login requirements in Mattermost by using userID-based authentication. It affects Mattermost instances configured to enforce SSO-only l...

CVE-2026-0997

MEDIUM CVSS 4.3 Feb 16, 2026

This vulnerability allows any authenticated Mattermost user to modify Zoom meeting restrictions for any channel via API requests. Affected systems include Mattermost versions 11.1.x up to 11.1.2, 10.1...

CVE-2026-22892

MEDIUM CVSS 4.3 Feb 13, 2026

This vulnerability allows authenticated Mattermost users with Jira plugin access to bypass channel permissions and read posts/attachments from channels they shouldn't have access to. Attackers can exp...

CVE-2025-14435

MEDIUM CVSS 6.8 Jan 16, 2026

This vulnerability allows authenticated Mattermost users to trigger infinite component re-render loops when API errors occur, causing application-level denial of service. Affected systems include Matt...

CVE-2025-64641

MEDIUM CVSS 4.1 Dec 24, 2025

This vulnerability allows malicious Mattermost users to create posts with fake Jira plugin actions that exfiltrate Jira tickets when other users interact with them. It affects Mattermost instances wit...

CVE-2025-13767

MEDIUM CVSS 4.3 Dec 24, 2025

This vulnerability allows authenticated Mattermost users with Jira plugin access to read posts and attachments from channels they shouldn't have access to. It affects Mattermost instances with the Jir...

CVE-2025-12689

MEDIUM CVSS 6.5 Dec 17, 2025

This vulnerability allows attackers to crash the Calls plugin in Mattermost by sending malformed WebSocket requests with improper UTF-8 formatting. Affected organizations are those running vulnerable ...

CVE-2025-62190

MEDIUM CVSS 4.3 Dec 17, 2025

This CSRF vulnerability in Mattermost allows authenticated attackers to initiate calls and inject messages into channels or direct messages via malicious webpages or links. It affects Mattermost versi...

CVE-2025-12756

MEDIUM CVSS 4.3 Dec 1, 2025

This vulnerability allows authenticated users with editor permissions in Mattermost Boards to delete comments created by other users, bypassing intended permission checks. It affects Mattermost instan...

CVE-2025-12559

MEDIUM CVSS 4.3 Nov 27, 2025

This vulnerability allows any authenticated Mattermost user to view team email addresses that should only be visible to Team Admins. The information disclosure occurs through the GET /api/v4/channels/...

CVE-2025-11794

MEDIUM CVSS 4.9 Nov 14, 2025

This vulnerability allows system administrators to access password hashes and MFA secrets through an API endpoint that fails to properly sanitize user data. It affects Mattermost instances running vul...

CVE-2025-55070

MEDIUM CVSS 6.5 Nov 14, 2025

Mattermost versions before 11 fail to enforce multi-factor authentication on WebSocket connections, allowing unauthenticated users to bypass MFA and access sensitive information via WebSocket events. ...

CVE-2025-55073

MEDIUM CVSS 5.4 Nov 14, 2025

This vulnerability allows attackers to edit arbitrary posts in Mattermost by exploiting an improper validation flaw in the MSTeams plugin OAuth flow. Attackers can craft malicious OAuth redirect URLs ...

CVE-2025-11776

MEDIUM CVSS 4.3 Nov 14, 2025

Mattermost versions before 11 have an authorization bypass vulnerability where guest users can discover archived public channels through a specific API endpoint. This allows unauthorized access to cha...

CVE-2025-41410

MEDIUM CVSS 5.4 Oct 16, 2025

This vulnerability allows attackers to create verified user accounts with arbitrary email domains during Slack imports in Mattermost. Attackers can bypass email-based team access restrictions by provi...

CVE-2025-41443

MEDIUM CVSS 4.3 Oct 16, 2025

This vulnerability allows guest users in Mattermost to discover active public channels and their metadata through an API endpoint, bypassing intended permission controls. It affects Mattermost instanc...

CVE-2025-9076

MEDIUM CVSS 6.5 Sep 15, 2025

Mattermost versions 10.10.x through 10.10.1 fail to properly sanitize user data during shared channel synchronization, allowing malicious remote clusters to access sensitive user information. This aff...

CVE-2025-9078

MEDIUM CVSS 4.3 Sep 15, 2025

This vulnerability allows authenticated Mattermost users to access unauthorized posts and manipulate link previews through hash collision attacks on FNV-1 hashing. It affects Mattermost versions 10.8....

CVE-2025-8402

MEDIUM CVSS 4.9 Aug 21, 2025

This vulnerability allows system administrators to crash Mattermost servers by importing malformed data through the bulk import feature. It affects Mattermost versions 10.8.x up to 10.8.3, 10.5.x up t...

CVE-2025-6465

MEDIUM CVSS 4.3 Aug 21, 2025

This vulnerability allows authenticated users with file upload permissions to overwrite file attachment thumbnails via path traversal in Mattermost's file streaming APIs. Attackers could potentially r...

CVE-2025-47870

MEDIUM CVSS 4.3 Aug 21, 2025

This vulnerability allows team administrators without member invite privileges to obtain a team's invite ID through the team restore API endpoint. Affected systems include Mattermost versions 10.8.x u...

CVE-2025-49222

MEDIUM CVSS 6.8 Aug 21, 2025

This vulnerability allows system administrators in Mattermost to upload non-attachment file types via shared channels, potentially placing files in arbitrary filesystem directories. It affects Matterm...

CVE-2025-8023

MEDIUM CVSS 6.8 Aug 21, 2025

This vulnerability allows system administrators in Mattermost to perform path traversal attacks by manipulating template file destination paths. Attackers can place malicious files outside intended di...

CVE-2025-36530

MEDIUM CVSS 6.8 Aug 21, 2025

This vulnerability allows restricted admin users in Mattermost to install unauthorized custom plugins via path traversal during plugin imports. It bypasses plugin signature enforcement and marketplace...

CVE-2025-6233

MEDIUM CVSS 6.8 Jul 18, 2025

This vulnerability allows system administrators in Mattermost to read arbitrary files on the server through path traversal in bulk import JSONL files. Attackers can exploit this by crafting malicious ...

CVE-2025-47871

MEDIUM CVSS 4.3 Jun 30, 2025

This vulnerability allows authenticated Mattermost users who are members of a playbook but not members of a linked private channel to access sensitive information about that channel through the run me...

CVE-2025-3227

MEDIUM CVSS 4.3 Jun 20, 2025

This vulnerability allows authenticated Mattermost users without proper channel management permissions to add or remove users from public and private channels by manipulating playbook run participants...

CVE-2025-4573

MEDIUM CVSS 4.1 Jun 11, 2025

This vulnerability allows authenticated Mattermost administrators with specific permissions to perform LDAP search filter injection when linking LDAP groups. Attackers could potentially extract sensit...

CVE-2026-20796

LOW CVSS 3.1 Feb 13, 2026

This vulnerability allows deactivated Mattermost users to learn team names they shouldn't have access to through a race condition in the API. It affects Mattermost versions 10.11.x up to 10.11.9. The ...

CVE-2025-14822

LOW CVSS 3.1 Jan 16, 2026

Mattermost versions 10.11.0 through 10.11.8 have a CPU exhaustion vulnerability where authenticated users can send posts with thousands of space-separated tokens that aren't properly validated before ...

CVE-2025-13324

LOW CVSS 3.7 Dec 17, 2025

This vulnerability allows attackers who obtain remote cluster invite tokens to authenticate as remote clusters and perform limited actions on shared channels in Mattermost, even after legitimate invit...

CVE-2025-62690

LOW CVSS 3.1 Dec 17, 2025

Mattermost versions 10.11.4 and earlier contain an open redirect vulnerability on the /error page. An attacker can craft a malicious link that redirects victims to arbitrary websites when opened in a ...

CVE-2025-13352

LOW CVSS 3.0 Dec 17, 2025

This vulnerability allows attackers to hijack Mattermost's GitHub reaction feature by exploiting improper plugin bot identity validation. Attackers can craft notification posts to make users add react...

CVE-2025-13870

LOW CVSS 3.1 Dec 2, 2025

This vulnerability in Mattermost allows authenticated users to access files and subscribe to blocks in Boards they shouldn't have permission to view. It affects Mattermost instances running vulnerable...

CVE-2025-41436

LOW CVSS 3.1 Nov 14, 2025

Mattermost versions before 11.0 fail to properly enforce the 'Allow users to view archived channels' setting, allowing regular users to access archived channel content and files via the 'Open in Chann...