Mattermost Security Vulnerabilities (CVEs)

Track 106 security vulnerabilities affecting Mattermost products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

5 Critical
18 High
74 Medium
9 Low
🔔 Get Alerts for Mattermost
CVE-2026-1628 4.6

The Mattermost Desktop App vulnerability allows malicious Mattermost servers to expose preload script functionality to untrusted external sites when u...

Mar 2, 2026
CVE-2025-14350 4.3

This vulnerability allows authenticated Mattermost users to discover the existence of teams and their URL names by posting channel shortlinks and obse...

Feb 16, 2026
CVE-2025-13821 5.7

This vulnerability allows authenticated Mattermost users to exfiltrate sensitive data including password hashes and MFA secrets through WebSocket mess...

Feb 16, 2026
CVE-2026-0999 5.4

This vulnerability allows authenticated users to bypass SSO-only login requirements in Mattermost by using userID-based authentication. It affects Mat...

Feb 16, 2026
CVE-2026-0997 4.3

This vulnerability allows any authenticated Mattermost user to modify Zoom meeting restrictions for any channel via API requests. Affected systems inc...

Feb 16, 2026
CVE-2026-22892 4.3

This vulnerability allows authenticated Mattermost users with Jira plugin access to bypass channel permissions and read posts/attachments from channel...

Feb 13, 2026
CVE-2026-20796 3.1

This vulnerability allows deactivated Mattermost users to learn team names they shouldn't have access to through a race condition in the API. It affec...

Feb 13, 2026
CVE-2025-13523 7.7

This cross-site scripting (XSS) vulnerability in Mattermost's Confluence plugin allows authenticated Confluence users with malicious display names to ...

Feb 6, 2026
CVE-2025-14435 6.8

This vulnerability allows authenticated Mattermost users to trigger infinite component re-render loops when API errors occur, causing application-leve...

Jan 16, 2026
CVE-2025-14822 3.1

Mattermost versions 10.11.0 through 10.11.8 have a CPU exhaustion vulnerability where authenticated users can send posts with thousands of space-separ...

Jan 16, 2026
CVE-2025-64641 4.1

This vulnerability allows malicious Mattermost users to create posts with fake Jira plugin actions that exfiltrate Jira tickets when other users inter...

Dec 24, 2025
CVE-2025-13767 4.3

This vulnerability allows authenticated Mattermost users with Jira plugin access to read posts and attachments from channels they shouldn't have acces...

Dec 24, 2025
CVE-2025-14273 7.2

This vulnerability allows unauthenticated attackers to bypass authentication in Mattermost's Jira plugin and make authenticated requests to Jira serve...

Dec 22, 2025
CVE-2025-13324 3.7

This vulnerability allows attackers who obtain remote cluster invite tokens to authenticate as remote clusters and perform limited actions on shared c...

Dec 17, 2025
CVE-2025-13326 3.9

Mattermost Desktop App versions before 6.0.0 for macOS fail to enable Hardened Runtime when packaged for the Mac App Store, allowing attackers to bypa...

Dec 17, 2025
CVE-2025-12689 6.5

This vulnerability allows attackers to crash the Calls plugin in Mattermost by sending malformed WebSocket requests with improper UTF-8 formatting. Af...

Dec 17, 2025
CVE-2025-13321 3.3

Mattermost Desktop App versions before 6.0.0 fail to properly clear sensitive information from logs and data when servers are deleted. This allows att...

Dec 17, 2025
CVE-2025-62190 4.3

This CSRF vulnerability in Mattermost allows authenticated attackers to initiate calls and inject messages into channels or direct messages via malici...

Dec 17, 2025
CVE-2025-62690 3.1

Mattermost versions 10.11.4 and earlier contain an open redirect vulnerability on the /error page. An attacker can craft a malicious link that redirec...

Dec 17, 2025
CVE-2025-13352 3.0

This vulnerability allows attackers to hijack Mattermost's GitHub reaction feature by exploiting improper plugin bot identity validation. Attackers ca...

Dec 17, 2025
CVE-2025-13870 3.1

This vulnerability in Mattermost allows authenticated users to access files and subscribe to blocks in Boards they shouldn't have permission to view. ...

Dec 2, 2025
CVE-2025-12756 4.3

This vulnerability allows authenticated users with editor permissions in Mattermost Boards to delete comments created by other users, bypassing intend...

Dec 1, 2025
CVE-2025-12421 9.9

This vulnerability allows authenticated Mattermost users to perform account takeover by exploiting a flaw in the SSO code exchange process. Attackers ...

Nov 27, 2025
CVE-2025-12559 4.3

This vulnerability allows any authenticated Mattermost user to view team email addresses that should only be visible to Team Admins. The information d...

Nov 27, 2025
CVE-2025-12419 9.9

This vulnerability allows authenticated attackers with team creation privileges to take over user accounts in Mattermost by manipulating OAuth state t...

Nov 27, 2025
CVE-2025-11794 4.9

This vulnerability allows system administrators to access password hashes and MFA secrets through an API endpoint that fails to properly sanitize user...

Nov 14, 2025
CVE-2025-41436 3.1

Mattermost versions before 11.0 fail to properly enforce the 'Allow users to view archived channels' setting, allowing regular users to access archive...

Nov 14, 2025
CVE-2025-55070 6.5

Mattermost versions before 11 fail to enforce multi-factor authentication on WebSocket connections, allowing unauthenticated users to bypass MFA and a...

Nov 14, 2025
CVE-2025-55073 5.4

This vulnerability allows attackers to edit arbitrary posts in Mattermost by exploiting an improper validation flaw in the MSTeams plugin OAuth flow. ...

Nov 14, 2025
CVE-2025-11776 4.3

Mattermost versions before 11 have an authorization bypass vulnerability where guest users can discover archived public channels through a specific AP...

Nov 14, 2025
CVE-2025-55035 6.1

This vulnerability in Mattermost Desktop App allows attackers to create a denial-of-service condition by tricking users into configuring a malicious s...

Oct 16, 2025
CVE-2025-58075 8.1

This vulnerability allows attackers to join any Mattermost team without proper authorization by manipulating RelayState parameters. Attackers can bypa...

Oct 16, 2025
CVE-2025-41410 5.4

This vulnerability allows attackers to create verified user accounts with arbitrary email domains during Slack imports in Mattermost. Attackers can by...

Oct 16, 2025
CVE-2025-41443 4.3

This vulnerability allows guest users in Mattermost to discover active public channels and their metadata through an API endpoint, bypassing intended ...

Oct 16, 2025
CVE-2025-9079 8.0

This vulnerability allows admin users in Mattermost to execute arbitrary code by uploading malicious plugins to the prepackaged plugins directory. The...

Sep 19, 2025
CVE-2025-9072 7.6

Mattermost SAML authentication redirect vulnerability allows attackers to steal user session cookies via malicious links. When users authenticate thro...

Sep 15, 2025
CVE-2025-9076 6.5

Mattermost versions 10.10.x through 10.10.1 fail to properly sanitize user data during shared channel synchronization, allowing malicious remote clust...

Sep 15, 2025
CVE-2025-9078 4.3

This vulnerability allows authenticated Mattermost users to access unauthorized posts and manipulate link previews through hash collision attacks on F...

Sep 15, 2025
CVE-2025-8402 4.9

This vulnerability allows system administrators to crash Mattermost servers by importing malformed data through the bulk import feature. It affects Ma...

Aug 21, 2025
CVE-2025-6465 4.3

This vulnerability allows authenticated users with file upload permissions to overwrite file attachment thumbnails via path traversal in Mattermost's ...

Aug 21, 2025
CVE-2025-47870 4.3

This vulnerability allows team administrators without member invite privileges to obtain a team's invite ID through the team restore API endpoint. Aff...

Aug 21, 2025
CVE-2025-49222 6.8

This vulnerability allows system administrators in Mattermost to upload non-attachment file types via shared channels, potentially placing files in ar...

Aug 21, 2025
CVE-2025-8023 6.8

This vulnerability allows system administrators in Mattermost to perform path traversal attacks by manipulating template file destination paths. Attac...

Aug 21, 2025
CVE-2025-36530 6.8

This vulnerability allows restricted admin users in Mattermost to install unauthorized custom plugins via path traversal during plugin imports. It byp...

Aug 21, 2025
CVE-2025-54463 5.9

The Mattermost Confluence Plugin before version 1.5.0 contains an improper input validation vulnerability that allows attackers to crash the plugin by...

Aug 11, 2025
CVE-2025-54478 7.2

The Mattermost Confluence Plugin before version 1.5.0 has an authentication bypass vulnerability that allows unauthenticated attackers to edit channel...

Aug 11, 2025
CVE-2025-53514 5.9

The Mattermost Confluence Plugin before version 1.5.0 contains an improper input validation vulnerability that allows attackers to crash the plugin by...

Aug 11, 2025
CVE-2025-53910 4.0

The Mattermost Confluence Plugin vulnerability allows attackers to create unauthorized channel subscriptions via API calls. This affects organizations...

Aug 11, 2025
CVE-2025-54458 5.0

The Mattermost Confluence Plugin before version 1.5.0 has an authorization bypass vulnerability where it fails to verify user permissions when creatin...

Aug 11, 2025
CVE-2025-52931 7.5

The Mattermost Confluence Plugin before version 1.5.0 contains an improper input validation vulnerability that allows attackers to crash the plugin by...

Aug 11, 2025

Why Monitor Mattermost Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 106+ known vulnerabilities affecting Mattermost products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Mattermost packages in under 60 seconds. No agents required - completely agentless scanning that works across Mattermost deployments.

Free vulnerability database: Access detailed information about every Mattermost CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Mattermost CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Mattermost CVEs Free