Skip to main content

Vendor archive

mattermost CVEs

Beta · best-effort

602 CVEs tagged to vendor mattermost21 Critical, 88 High, 367 Medium, 126 Low, 0 Unrated.

CVE-2026-25780

Published Mar 16, 2026

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cau…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24458

Published Mar 16, 2026

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and me…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1628

Published Mar 2, 2026

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose prel…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1046

Published Feb 16, 2026

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14573

Published Feb 16, 2026

Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restri…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-14350

Published Feb 16, 2026

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated us…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13821

Published Feb 16, 2026

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate pas…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-0999

Published Feb 16, 2026

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-onl…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0998

Published Feb 16, 2026

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0997

Published Feb 16, 2026

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22892

Published Feb 13, 2026

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authe…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-20796

Published Feb 13, 2026

Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should n…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13523

Published Feb 6, 2026

Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with mali…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14435

Published Jan 16, 2026

Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14822

Published Jan 16, 2026

Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP req…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64641

Published Dec 24, 2025

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13767

Published Dec 24, 2025

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comment…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14273

Published Dec 22, 2025

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enf…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13326

Published Dec 17, 2025

Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC pe…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-13324

Published Dec 17, 2025

Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-13321

Published Dec 17, 2025

Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the us…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-12689

Published Dec 17, 2025

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls pl…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62690

Published Dec 17, 2025

Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link open…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-62190

Published Dec 17, 2025

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page whic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13352

Published Dec 17, 2025

Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack t…

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort
Showing 101-125 of 602 CVEsPage 5 of 25