Mattermost Security Vulnerabilities (CVEs)
Track 106 security vulnerabilities affecting Mattermost products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
The Mattermost Confluence Plugin before version 1.5.0 has an authorization bypass vulnerability where attackers can retrieve channel subscription deta...
Aug 11, 2025The Mattermost Confluence Plugin before version 1.5.0 has an authorization bypass vulnerability that allows attackers to create unauthorized channel s...
Aug 11, 2025This vulnerability allows system administrators in Mattermost to read arbitrary files on the server through path traversal in bulk import JSONL files....
Jul 18, 2025This vulnerability allows authenticated Mattermost users who are members of a playbook but not members of a linked private channel to access sensitive...
Jun 30, 2025This vulnerability allows authenticated Mattermost users without proper channel management permissions to add or remove users from public and private ...
Jun 20, 2025This vulnerability allows authenticated Mattermost users to write files to arbitrary locations on the filesystem by uploading archives containing path...
Jun 20, 2025This vulnerability allows authenticated Mattermost administrators with specific permissions to perform LDAP search filter injection when linking LDAP ...
Jun 11, 2025Mattermost fails to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bo...
May 30, 2025Mattermost fails to implement account lockout for LDAP users after repeated failed login attempts, allowing attackers to perform denial-of-service att...
May 15, 2025This vulnerability allows attackers to create task items with excessive actions via the UpdateRunTaskActions GraphQL operation, causing server overloa...
Apr 24, 2025This vulnerability allows authenticated users to view metadata from archived channels even when the 'Allow Users to View Archived Channels' setting is...
Apr 16, 2025Mattermost fails to invalidate user cache when converting accounts to bots, allowing attackers to log in once using the original user credentials. Thi...
Apr 14, 2025This vulnerability allows delegated granular administration users with 'Edit Other Users' permission to modify system administrator accounts in Matter...
Apr 14, 2025Mattermost Mobile Apps versions up to 2.25.0 contain a GIF validation vulnerability that allows attackers to crash the Android application by sending ...
Mar 24, 2025Mattermost fails to enforce channel conversion restrictions, allowing users with permission to convert public channels to private to also convert priv...
Mar 21, 2025Mattermost fails to restrict bookmark creation and updates in archived channels, allowing authenticated users to create or modify bookmarks in channel...
Mar 21, 2025Mattermost fails to enforce multi-factor authentication (MFA) on plugin endpoints, allowing authenticated attackers to bypass MFA protections via API ...
Mar 21, 2025This vulnerability allows authenticated users to execute slash commands in archived Mattermost channels, bypassing intended restrictions. It affects M...
Mar 21, 2025Mattermost versions 9.11.x through 9.11.8 have an authorization flaw where users with the Viewer role configured with 'No Access to Reporting' can sti...
Mar 19, 2025This vulnerability in Mattermost Boards allows authenticated users to read arbitrary files on the server by duplicating specially crafted blocks. It a...
Feb 24, 2025This vulnerability allows authenticated Mattermost users to export archived channel contents even when the 'Allow users to view archived channels' set...
Feb 24, 2025This vulnerability in Mattermost Boards allows attackers to read arbitrary files on the server by importing specially crafted board archives. It affec...
Feb 24, 2025Mattermost Mobile versions up to 2.22.0 contain a type casting vulnerability where posts with attachments containing non-String fields can crash the m...
Jan 16, 2025Mattermost Mobile Apps versions up to 2.22.0 contain a vulnerability where specially crafted attachment names can cause the mobile app to crash when a...
Jan 16, 2025Mattermost fails to properly validate post properties, allowing authenticated malicious users to crash the server by sending specially crafted posts. ...
Jan 15, 2025Mattermost Mobile Apps versions up to 2.22.0 fail to properly validate post properties, allowing authenticated malicious users to send specially craft...
Jan 15, 2025This vulnerability in Mattermost allows attackers to create denial-of-service conditions by exploiting improper validation of post types. Attackers wi...
Jan 9, 2025Mattermost Android mobile apps up to version 2.21.0 have a misconfigured file provider that allows local attackers to access sensitive files. This aff...
Dec 16, 2024This vulnerability in Mattermost allows authenticated users to send specially crafted posts that cause denial-of-service conditions for other users in...
Dec 16, 2024Mattermost fails to properly propagate permission scheme updates across cluster nodes, allowing users to retain old permissions even after administrat...
Dec 5, 2024This vulnerability allows unauthenticated attackers to bypass email domain restrictions in Mattermost by submitting specially crafted email addresses ...
Nov 28, 2024This vulnerability in Mattermost allows attackers to discover private channel names they shouldn't have access to when using Elasticsearch v8 with the...
Nov 9, 2024Mattermost fails to sanitize user inputs in the frontend that are used for redirection, allowing a one-click client-side path traversal that leads to ...
Oct 29, 2024This vulnerability allows attackers to bypass authorization controls in Mattermost when archived channel viewing is disabled. Attackers can retrieve p...
Sep 26, 2024Mattermost mobile apps version 2.18.0 and earlier fail to disable autocomplete during password entry when visible password mode is selected. This allo...
Sep 16, 2024This vulnerability in Mattermost allows authenticated users to manipulate the creation date of their accounts via the POST /api/v4/users endpoint, tri...
Aug 22, 2024This vulnerability allows users with edit access to the permissions section of the Mattermost system console to escalate their privileges to System Ad...
Aug 22, 2024This vulnerability in Mattermost exposes remote users' email addresses when shared channels are enabled, even when email visibility is otherwise restr...
Aug 22, 2024This vulnerability allows remote/synthetic users created through shared channels to receive email notifications and reset passwords using munged email...
Aug 22, 2024This vulnerability in Mattermost allows a malicious remote attacker to create, update, or delete arbitrary posts in arbitrary channels when shared cha...
Aug 1, 2024This vulnerability in Mattermost allows remote attackers to forcibly share local channels without administrator consent when shared channels are enabl...
Aug 1, 2024This vulnerability allows users on remote Mattermost servers to set arbitrary usernames that sync to local servers when shared channels are enabled. I...
Aug 1, 2024This vulnerability in Mattermost allows a malicious remote user in a shared channel to overwrite an existing local user's account. This affects Matter...
Aug 1, 2024Mattermost mobile apps up to version 2.16.0 fail to properly validate push notification origins, allowing malicious servers to impersonate legitimate ...
Jul 15, 2024Mattermost versions with shared channels enabled are vulnerable to a timing attack that allows retrieval of remote cluster tokens. Attackers can explo...
Jul 3, 2024Mattermost Desktop App versions up to 5.7.0 fail to properly prompt users for permission when opening external URLs, allowing attackers to force victi...
Jun 14, 2024This vulnerability allows attackers to execute slash commands as other users by creating deceptive post actions in Mattermost. Attackers can trick use...
May 26, 2024This vulnerability in Mattermost allows guest users on channels with linked playbook runs to view all details of those runs when marked as finished. I...
May 26, 2024This vulnerability allows Mattermost users to link their playbook runs to private channels they don't have access to, bypassing intended access contro...
May 26, 2024This vulnerability allows guest users in Mattermost to access metadata of public playbook runs linked to channels they are guests in, bypassing intend...
May 26, 2024Why Monitor Mattermost Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 106+ known vulnerabilities affecting Mattermost products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Mattermost packages in under 60 seconds. No agents required - completely agentless scanning that works across Mattermost deployments.
Free vulnerability database: Access detailed information about every Mattermost CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Mattermost CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions