Skip to main content

Vendor/product archive

mattermost / mattermost_server CVEs

Beta · best-effort

452 CVEs tagged to mattermost / mattermost_server17 Critical, 63 High, 283 Medium, 89 Low, 0 Unrated.

CVE-2025-24866

Published Apr 10, 2025

Mattermost versions 9.11.x <= 9.11.8  fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack a…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-30179

Published Mar 21, 2025

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27933

Published Mar 21, 2025

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert p…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27715

Published Mar 21, 2025

Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafte…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-25274

Published Mar 21, 2025

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25068

Published Mar 21, 2025

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24920

Published Mar 21, 2025

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authen…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1472

Published Mar 19, 2025

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25279

Published Feb 24, 2025

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker co…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24526

Published Feb 24, 2025

Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24490

Published Feb 24, 2025

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an at…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-20051

Published Feb 24, 2025

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a us…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-1412

Published Feb 24, 2025

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their pri…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-0503

Published Feb 14, 2025

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if so…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-20621

Published Jan 16, 2025

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20088

Published Jan 15, 2025

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to caus…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20086

Published Jan 15, 2025

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to caus…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21088

Published Jan 15, 2025

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22449

Published Jan 9, 2025

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating th…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-22445

Published Jan 9, 2025

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-20033

Published Jan 9, 2025

Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sys…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54682

Published Dec 16, 2024

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54083

Published Dec 16, 2024

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client sid…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48872

Published Dec 16, 2024

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which a…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12247

Published Dec 5, 2024

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old per…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 452 CVEsPage 8 of 19