Skip to main content

Vendor archive

mattermost CVEs

Beta · best-effort

602 CVEs tagged to vendor mattermost21 Critical, 88 High, 367 Medium, 126 Low, 0 Unrated.

CVE-2025-13870

Published Dec 2, 2025

Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an aut…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-12756

Published Dec 1, 2025

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12421

Published Nov 27, 2025

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-12559

Published Nov 27, 2025

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12419

Published Nov 27, 2025

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication w…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-55074

Published Nov 18, 2025

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channel…

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-11794

Published Nov 14, 2025

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and MFA secre…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55073

Published Nov 14, 2025

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow wh…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55070

Published Nov 14, 2025

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-41436

Published Nov 14, 2025

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-11776

Published Nov 14, 2025

Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59480

Published Nov 13, 2025

Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacke…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11777

Published Nov 13, 2025

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to a…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-55035

Published Oct 16, 2025

Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their se…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58075

Published Oct 16, 2025

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58073

Published Oct 16, 2025

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54499

Published Oct 16, 2025

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-41410

Published Oct 16, 2025

Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verifie…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10545

Published Oct 16, 2025

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team mem…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-41443

Published Oct 16, 2025

Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58084

Published Oct 13, 2025

Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash th…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9081

Published Sep 19, 2025

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file do…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9079

Published Sep 19, 2025

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows a…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9084

Published Sep 15, 2025

Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9072

Published Sep 15, 2025

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 602 CVEsPage 6 of 25