github.com/mattermost/mattermost-server
Mattermost is an open source platform for secure collaboration across the entire software development lifecycle..
Activity
- Latest release
- 1mo ago
- Total releases
- 67
- Cadence
- ~9 days
- Last 12 months
- 26
Reach
- Stars
- 38.9k
Details
- First release
- Apr 26, 2017
| Version | Released | |
|---|---|---|
v11.8.5+incompatible
patch
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.5+incompatible
patch
|
|
v11.8.5-rc1+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.5-rc1+incompatible
pre
|
|
v11.9.1+incompatible
patch
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.9.1+incompatible
patch
|
|
v11.9.1-rc1+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.9.1-rc1+incompatible
pre
|
|
v11.8.4+incompatible
patch
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.4+incompatible
patch
|
|
v11.9.0+incompatible
minor
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.9.0+incompatible
minor
|
|
v11.8.3+incompatible
patch
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.3+incompatible
patch
|
|
v11.9.0-rc3+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.9.0-rc3+incompatible
pre
|
|
v11.9.0-rc2+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.9.0-rc2+incompatible
pre
|
|
v11.7.6+incompatible
minor
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.7.6+incompatible
minor
|
|
v11.8.2+incompatible
patch
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.2+incompatible
patch
|
|
v11.9.0-rc1+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.9.0-rc1+incompatible
pre
|
|
v11.8.1+incompatible
patch
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.1+incompatible
patch
|
|
v11.8.0+incompatible
minor
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.0+incompatible
minor
|
|
v11.8.0-rc5+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.0-rc5+incompatible
pre
|
|
v11.8.0-rc4+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.0-rc4+incompatible
pre
|
|
v11.8.0-rc3+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.0-rc3+incompatible
pre
|
|
v11.8.0-rc2+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.0-rc2+incompatible
pre
|
|
v11.8.0-rc1+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.8.0-rc1+incompatible
pre
|
|
v11.7.0-rc1+incompatible
pre
44 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.7.0-rc1+incompatible
pre
|
|
v11.2.1-rc1+incompatible
pre
69 CVEs
CVE-2026-3114
GO-2026-5663
GHSA-vhgh-g7x8-4rx8
Jun 25, 2026
Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27659
GO-2026-5629
GHSA-rmhw-c3xr-m3xx
Jun 25, 2026
Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3115
GO-2026-5512
GHSA-mpc7-mm28-f6wq
Jun 25, 2026
Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4274
GO-2026-5393
GHSA-g7fp-cqj5-x8hf
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27656
GO-2026-5360
GHSA-fg35-5rf6-qg3g
Jun 25, 2026
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20719
GO-2026-5245
GHSA-86vc-mg26-fj6x
Jun 25, 2026
Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server Fixed in
10.11.2+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3112
GO-2026-5092
GHSA-3mw5-466q-295q
Jun 25, 2026
Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3113
GO-2026-5112
GHSA-4765-v66x-rqx7
Jun 25, 2026
Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20260105080200-d27a2195068d before v8.0.0-20260217110922-b7d4a1f1f59b. Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3108
GO-2026-5067
GHSA-3439-vqgj-2gcf
Jun 25, 2026
Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-26233
GO-2026-4916
GHSA-247x-7qw8-fp98
Apr 02, 2026
Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20260105080200-d27a2195068d before v8.0.0-20260217110922-b7d4a1f1f59b. Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-2456
GO-2026-4726
GHSA-34g8-9fpp-46ch
Mar 26, 2026
Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127165411-fe3052073dc6. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-25783
GO-2026-4725
GHSA-2v3w-6g35-5f9v
Mar 26, 2026
Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129181235-1346cf529aef. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-22545
GO-2026-4786
GHSA-rv67-7w2g-7976
Mar 23, 2026
Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127144908-ced9a56e3988. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-4265
GO-2026-4749
GHSA-xpvf-6qcc-9jqc
Mar 23, 2026
Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107144005-c7f6efdfb035. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-21386
GO-2026-4744
GHSA-5mr9-crcg-8wh2
Mar 23, 2026
Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260130144323-5bb5261c72fa. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26246
GO-2026-4727
GHSA-44mv-jq72-gj49
Mar 23, 2026
Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260115183946-38b413a27604. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-24692
GO-2026-4745
GHSA-cwfj-642j-gfh4
Mar 23, 2026
Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107142155-0481bd1fb045. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2458
GO-2026-4729
GHSA-679f-wmrg-qf57
Mar 23, 2026
Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260113182106-a18b80ba4c32. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24458
GO-2026-4731
GHSA-m5rv-56xx-hfc6
Mar 23, 2026
Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129164748-7201f42d955f. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2578
GO-2026-4734
GHSA-3rhr-jr63-hwq5
Mar 23, 2026
Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127062706-c6b205f0d770. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2455
GO-2026-4746
GHSA-gqv7-j2j8-qmwq
Mar 23, 2026
Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129133647-5d787969c2d5. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2457
GO-2026-4732
GHSA-ph22-fw5m-w2q9
Mar 23, 2026
Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123211116-9efe617be8b8. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25780
GO-2026-4733
GHSA-xv2p-wchj-qjhp
Mar 23, 2026
Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123215601-86797c508c44. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2463
GO-2026-4735
GHSA-fx49-m253-27jj
Mar 23, 2026
Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260105134819-cc427af41b2a. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-22892
GO-2026-4496
GHSA-9pj7-jh2r-87g8
Feb 23, 2026
Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts in github.com/mattermost/mattermost-server Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts in github.com/mattermost/mattermost-server Fixed in
10.11.10+incompatible
11.1.3+incompatible
11.2.2+incompatible
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.2.1-rc1+incompatible
pre
|
|
v10.11.9+incompatible
patch
104 CVEs
CVE-2026-7184
GO-2026-6282
GHSA-9p44-r552-4wp9
Aug 25, 2026
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server Fixed in
10.11.16+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-7387
GO-2026-6280
GHSA-6hxm-w4hv-vgvw
Aug 25, 2026
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6046
GO-2026-6279
GHSA-3vmp-whvv-5v9v
Aug 25, 2026
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-3433
GO-2026-6286
GHSA-rp4v-qc77-phm4
Aug 25, 2026
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6689
GO-2026-6283
GHSA-c28q-m4gf-vg4q
Aug 25, 2026
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6961
GO-2026-6281
GHSA-8qq9-cqj8-82w4
Aug 25, 2026
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6739
GO-2026-6285
GHSA-m2w9-h2mm-79qr
Aug 25, 2026
Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5740
GO-2026-5838
GHSA-w9m8-p4cc-4qj9
Jul 07, 2026
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-3473
GO-2026-5817
GHSA-7pf2-9c95-w332
Jul 07, 2026
Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-4915
GO-2026-5845
GHSA-5gmf-x7hg-97wf
Jul 07, 2026
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-4635
GO-2026-5820
GHSA-pg7c-462j-grxv
Jul 07, 2026
Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5755
GO-2026-5835
GHSA-37j2-3vv8-cf24
Jul 07, 2026
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-3636
GO-2026-5818
GHSA-ffpr-pfr4-g354
Jul 07, 2026
Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28732
GO-2026-5726
GHSA-wvcv-9xpm-7mqc
Jun 25, 2026
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260306123948-f5fe8ded6b63. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6333
GO-2026-5671
GHSA-vqp5-2mrp-qqxg
Jun 25, 2026
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260325160634-e738016c5920. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6345
GO-2026-5727
GHSA-wvgv-4fc3-2rcp
Jun 25, 2026
Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260311102650-3057ae7e83e9. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3114
GO-2026-5663
GHSA-vhgh-g7x8-4rx8
Jun 25, 2026
Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3637
GO-2026-5651
GHSA-v549-xx3c-6pc8
Jun 25, 2026
Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260316171743-090408f09f53. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27659
GO-2026-5629
GHSA-rmhw-c3xr-m3xx
Jun 25, 2026
Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3115
GO-2026-5512
GHSA-mpc7-mm28-f6wq
Jun 25, 2026
Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6334
GO-2026-5474
GHSA-jp3f-x449-4q75
Jun 25, 2026
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260318173148-e9ae890a013b. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4273
GO-2026-5432
GHSA-hqpj-f3jh-29vx
Jun 25, 2026
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260313190740-742e0be95074. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3495
GO-2026-5484
GHSA-jx93-pf6x-874r
Jun 25, 2026
Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260310115442-5a1ea95044dc; github.com/mattermost/mattermost/server/v8 before v8.0.0-20260310115442-5a1ea95044d. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-2325
GO-2026-5489
GHSA-m3p3-8frq-q7qh
Jun 25, 2026
Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6343
GO-2026-5494
GHSA-m79q-8qf5-v622
Jun 25, 2026
Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3590
GO-2026-5507
GHSA-mh4x-rmrx-3hp4
Jun 25, 2026
Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server Fixed in
10.11.13+incompatible
11.3.3+incompatible
11.4.3+incompatible
11.5.0+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4286
GO-2026-5404
GHSA-gvg4-jhmr-6j23
Jun 25, 2026
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6346
GO-2026-5293
GHSA-9p64-jpc7-m2rp
Jun 25, 2026
Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260326202606-fac92f4a71f3. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4274
GO-2026-5393
GHSA-g7fp-cqj5-x8hf
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4858
GO-2026-5311
GHSA-c4r7-j7pp-r8mp
Jun 25, 2026
Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6340
GO-2026-5325
GHSA-cjm8-jxpw-g43m
Jun 25, 2026
Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260325191733-fb11968f8798. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27656
GO-2026-5360
GHSA-fg35-5rf6-qg3g
Jun 25, 2026
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6347
GO-2026-5238
GHSA-82j6-4fq7-fx62
Jun 25, 2026
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-28759
GO-2026-5256
GHSA-8h9w-w78c-vvr3
Jun 25, 2026
Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260216150504-8738f8c4b3d4. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3112
GO-2026-5092
GHSA-3mw5-466q-295q
Jun 25, 2026
Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3113
GO-2026-5112
GHSA-4765-v66x-rqx7
Jun 25, 2026
Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20260105080200-d27a2195068d before v8.0.0-20260217110922-b7d4a1f1f59b. Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3108
GO-2026-5067
GHSA-3439-vqgj-2gcf
Jun 25, 2026
Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-26233
GO-2026-4916
GHSA-247x-7qw8-fp98
Apr 02, 2026
Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20260105080200-d27a2195068d before v8.0.0-20260217110922-b7d4a1f1f59b. Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-2456
GO-2026-4726
GHSA-34g8-9fpp-46ch
Mar 26, 2026
Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127165411-fe3052073dc6. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-25783
GO-2026-4725
GHSA-2v3w-6g35-5f9v
Mar 26, 2026
Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129181235-1346cf529aef. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-22545
GO-2026-4786
GHSA-rv67-7w2g-7976
Mar 23, 2026
Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127144908-ced9a56e3988. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-4265
GO-2026-4749
GHSA-xpvf-6qcc-9jqc
Mar 23, 2026
Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107144005-c7f6efdfb035. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-21386
GO-2026-4744
GHSA-5mr9-crcg-8wh2
Mar 23, 2026
Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260130144323-5bb5261c72fa. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26246
GO-2026-4727
GHSA-44mv-jq72-gj49
Mar 23, 2026
Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260115183946-38b413a27604. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-24692
GO-2026-4745
GHSA-cwfj-642j-gfh4
Mar 23, 2026
Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107142155-0481bd1fb045. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2458
GO-2026-4729
GHSA-679f-wmrg-qf57
Mar 23, 2026
Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260113182106-a18b80ba4c32. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24458
GO-2026-4731
GHSA-m5rv-56xx-hfc6
Mar 23, 2026
Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129164748-7201f42d955f. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2578
GO-2026-4734
GHSA-3rhr-jr63-hwq5
Mar 23, 2026
Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127062706-c6b205f0d770. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2455
GO-2026-4746
GHSA-gqv7-j2j8-qmwq
Mar 23, 2026
Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129133647-5d787969c2d5. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2457
GO-2026-4732
GHSA-ph22-fw5m-w2q9
Mar 23, 2026
Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123211116-9efe617be8b8. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25780
GO-2026-4733
GHSA-xv2p-wchj-qjhp
Mar 23, 2026
Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123215601-86797c508c44. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2463
GO-2026-4735
GHSA-fx49-m253-27jj
Mar 23, 2026
Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260105134819-cc427af41b2a. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-20796
GO-2026-4495
GHSA-2xf7-hmf6-p64j
Feb 23, 2026
Mattermost doesn't properly validate channel membership at the time of data retrieval in github.com/mattermost/mattermost-server Mattermost doesn't properly validate channel membership at the time of data retrieval in github.com/mattermost/mattermost-server Fixed in
10.11.10+incompatible
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-22892
GO-2026-4496
GHSA-9pj7-jh2r-87g8
Feb 23, 2026
Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts in github.com/mattermost/mattermost-server Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts in github.com/mattermost/mattermost-server Fixed in
10.11.10+incompatible
11.1.3+incompatible
11.2.2+incompatible
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.11.9+incompatible
patch
|
|
v11.0.7+incompatible
major
46 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14822
GO-2026-4325
GHSA-9r42-rhw3-2222
Feb 26, 2026
Mattermost is vulnerable to CPU exhaustion via crafted HTTP request in github.com/mattermost/mattermost-server Mattermost is vulnerable to CPU exhaustion via crafted HTTP request in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.11.9+incompatible
11.2.0+incompatible
References
Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v11.0.7+incompatible
major
|
|
v10.11.7+incompatible
patch
108 CVEs
CVE-2026-7184
GO-2026-6282
GHSA-9p44-r552-4wp9
Aug 25, 2026
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server Fixed in
10.11.16+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-7387
GO-2026-6280
GHSA-6hxm-w4hv-vgvw
Aug 25, 2026
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6046
GO-2026-6279
GHSA-3vmp-whvv-5v9v
Aug 25, 2026
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-3433
GO-2026-6286
GHSA-rp4v-qc77-phm4
Aug 25, 2026
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6689
GO-2026-6283
GHSA-c28q-m4gf-vg4q
Aug 25, 2026
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6961
GO-2026-6281
GHSA-8qq9-cqj8-82w4
Aug 25, 2026
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6739
GO-2026-6285
GHSA-m2w9-h2mm-79qr
Aug 25, 2026
Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5740
GO-2026-5838
GHSA-w9m8-p4cc-4qj9
Jul 07, 2026
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-3473
GO-2026-5817
GHSA-7pf2-9c95-w332
Jul 07, 2026
Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-4915
GO-2026-5845
GHSA-5gmf-x7hg-97wf
Jul 07, 2026
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-4635
GO-2026-5820
GHSA-pg7c-462j-grxv
Jul 07, 2026
Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5755
GO-2026-5835
GHSA-37j2-3vv8-cf24
Jul 07, 2026
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-3636
GO-2026-5818
GHSA-ffpr-pfr4-g354
Jul 07, 2026
Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28732
GO-2026-5726
GHSA-wvcv-9xpm-7mqc
Jun 25, 2026
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260306123948-f5fe8ded6b63. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6333
GO-2026-5671
GHSA-vqp5-2mrp-qqxg
Jun 25, 2026
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260325160634-e738016c5920. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6345
GO-2026-5727
GHSA-wvgv-4fc3-2rcp
Jun 25, 2026
Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260311102650-3057ae7e83e9. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3114
GO-2026-5663
GHSA-vhgh-g7x8-4rx8
Jun 25, 2026
Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3637
GO-2026-5651
GHSA-v549-xx3c-6pc8
Jun 25, 2026
Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260316171743-090408f09f53. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27659
GO-2026-5629
GHSA-rmhw-c3xr-m3xx
Jun 25, 2026
Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3115
GO-2026-5512
GHSA-mpc7-mm28-f6wq
Jun 25, 2026
Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6334
GO-2026-5474
GHSA-jp3f-x449-4q75
Jun 25, 2026
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260318173148-e9ae890a013b. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4273
GO-2026-5432
GHSA-hqpj-f3jh-29vx
Jun 25, 2026
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260313190740-742e0be95074. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3495
GO-2026-5484
GHSA-jx93-pf6x-874r
Jun 25, 2026
Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260310115442-5a1ea95044dc; github.com/mattermost/mattermost/server/v8 before v8.0.0-20260310115442-5a1ea95044d. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-2325
GO-2026-5489
GHSA-m3p3-8frq-q7qh
Jun 25, 2026
Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6343
GO-2026-5494
GHSA-m79q-8qf5-v622
Jun 25, 2026
Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3590
GO-2026-5507
GHSA-mh4x-rmrx-3hp4
Jun 25, 2026
Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server Fixed in
10.11.13+incompatible
11.3.3+incompatible
11.4.3+incompatible
11.5.0+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4286
GO-2026-5404
GHSA-gvg4-jhmr-6j23
Jun 25, 2026
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6346
GO-2026-5293
GHSA-9p64-jpc7-m2rp
Jun 25, 2026
Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260326202606-fac92f4a71f3. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4274
GO-2026-5393
GHSA-g7fp-cqj5-x8hf
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4858
GO-2026-5311
GHSA-c4r7-j7pp-r8mp
Jun 25, 2026
Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6340
GO-2026-5325
GHSA-cjm8-jxpw-g43m
Jun 25, 2026
Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260325191733-fb11968f8798. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27656
GO-2026-5360
GHSA-fg35-5rf6-qg3g
Jun 25, 2026
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6347
GO-2026-5238
GHSA-82j6-4fq7-fx62
Jun 25, 2026
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-28759
GO-2026-5256
GHSA-8h9w-w78c-vvr3
Jun 25, 2026
Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260216150504-8738f8c4b3d4. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3112
GO-2026-5092
GHSA-3mw5-466q-295q
Jun 25, 2026
Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3113
GO-2026-5112
GHSA-4765-v66x-rqx7
Jun 25, 2026
Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20260105080200-d27a2195068d before v8.0.0-20260217110922-b7d4a1f1f59b. Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3108
GO-2026-5067
GHSA-3439-vqgj-2gcf
Jun 25, 2026
Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-26233
GO-2026-4916
GHSA-247x-7qw8-fp98
Apr 02, 2026
Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20260105080200-d27a2195068d before v8.0.0-20260217110922-b7d4a1f1f59b. Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-2456
GO-2026-4726
GHSA-34g8-9fpp-46ch
Mar 26, 2026
Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127165411-fe3052073dc6. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-25783
GO-2026-4725
GHSA-2v3w-6g35-5f9v
Mar 26, 2026
Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129181235-1346cf529aef. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-22545
GO-2026-4786
GHSA-rv67-7w2g-7976
Mar 23, 2026
Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127144908-ced9a56e3988. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-4265
GO-2026-4749
GHSA-xpvf-6qcc-9jqc
Mar 23, 2026
Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107144005-c7f6efdfb035. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-21386
GO-2026-4744
GHSA-5mr9-crcg-8wh2
Mar 23, 2026
Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260130144323-5bb5261c72fa. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26246
GO-2026-4727
GHSA-44mv-jq72-gj49
Mar 23, 2026
Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260115183946-38b413a27604. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-24692
GO-2026-4745
GHSA-cwfj-642j-gfh4
Mar 23, 2026
Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107142155-0481bd1fb045. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2458
GO-2026-4729
GHSA-679f-wmrg-qf57
Mar 23, 2026
Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260113182106-a18b80ba4c32. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24458
GO-2026-4731
GHSA-m5rv-56xx-hfc6
Mar 23, 2026
Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129164748-7201f42d955f. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2578
GO-2026-4734
GHSA-3rhr-jr63-hwq5
Mar 23, 2026
Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127062706-c6b205f0d770. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2455
GO-2026-4746
GHSA-gqv7-j2j8-qmwq
Mar 23, 2026
Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129133647-5d787969c2d5. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2457
GO-2026-4732
GHSA-ph22-fw5m-w2q9
Mar 23, 2026
Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123211116-9efe617be8b8. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25780
GO-2026-4733
GHSA-xv2p-wchj-qjhp
Mar 23, 2026
Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123215601-86797c508c44. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2463
GO-2026-4735
GHSA-fx49-m253-27jj
Mar 23, 2026
Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260105134819-cc427af41b2a. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-13767
GO-2025-4259
GHSA-fmqf-pmcm-8cx9
Feb 26, 2026
Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues in github.com/mattermost/mattermost-server Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20251121122154-b57c297c6d7. Fixed in
10.11.8+incompatible
10.12.4+incompatible
11.0.6+incompatible
11.1.1+incompatible
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-14435
GO-2026-4326
GHSA-mx8m-v8qm-xwr8
Feb 26, 2026
Mattermost is vulnerable to DoS due to infinite re-renders on API errors in github.com/mattermost/mattermost-server Mattermost is vulnerable to DoS due to infinite re-renders on API errors in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.11.9+incompatible
11.0.7+incompatible
11.1.2+incompatible
References
Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-64641
GO-2025-4260
GHSA-vww6-79rv-3j4x
Feb 26, 2026
Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin in github.com/mattermost/mattermost-server Mattermost doesn't verify that post actions invoking NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20251121122154-b57c297c6d7. Fixed in
10.11.8+incompatible
10.12.4+incompatible
11.0.6+incompatible
11.1.1+incompatible
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-14822
GO-2026-4325
GHSA-9r42-rhw3-2222
Feb 26, 2026
Mattermost is vulnerable to CPU exhaustion via crafted HTTP request in github.com/mattermost/mattermost-server Mattermost is vulnerable to CPU exhaustion via crafted HTTP request in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.11.9+incompatible
11.2.0+incompatible
References
Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-20796
GO-2026-4495
GHSA-2xf7-hmf6-p64j
Feb 23, 2026
Mattermost doesn't properly validate channel membership at the time of data retrieval in github.com/mattermost/mattermost-server Mattermost doesn't properly validate channel membership at the time of data retrieval in github.com/mattermost/mattermost-server Fixed in
10.11.10+incompatible
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-22892
GO-2026-4496
GHSA-9pj7-jh2r-87g8
Feb 23, 2026
Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts in github.com/mattermost/mattermost-server Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts in github.com/mattermost/mattermost-server Fixed in
10.11.10+incompatible
11.1.3+incompatible
11.2.2+incompatible
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.11.7+incompatible
patch
|
|
v10.5.13+incompatible
patch
46 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.5.13+incompatible
patch
|
|
v10.5.12+incompatible
minor
46 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.5.12+incompatible
minor
|
|
v10.11.1+incompatible
minor
118 CVEs
CVE-2026-7184
GO-2026-6282
GHSA-9p44-r552-4wp9
Aug 25, 2026
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server Fixed in
10.11.16+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-7387
GO-2026-6280
GHSA-6hxm-w4hv-vgvw
Aug 25, 2026
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6046
GO-2026-6279
GHSA-3vmp-whvv-5v9v
Aug 25, 2026
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-3433
GO-2026-6286
GHSA-rp4v-qc77-phm4
Aug 25, 2026
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6689
GO-2026-6283
GHSA-c28q-m4gf-vg4q
Aug 25, 2026
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6961
GO-2026-6281
GHSA-8qq9-cqj8-82w4
Aug 25, 2026
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-6739
GO-2026-6285
GHSA-m2w9-h2mm-79qr
Aug 25, 2026
Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server Fixed in
10.11.17+incompatible
11.5.5+incompatible
11.6.1+incompatible
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-5308
GO-2026-5836
GHSA-jmvr-r5hm-fxfr
Jul 07, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5740
GO-2026-5838
GHSA-w9m8-p4cc-4qj9
Jul 07, 2026
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-4646
GO-2026-5833
GHSA-rmvv-8v8w-rf7x
Jul 07, 2026
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-3473
GO-2026-5817
GHSA-7pf2-9c95-w332
Jul 07, 2026
Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-4915
GO-2026-5845
GHSA-5gmf-x7hg-97wf
Jul 07, 2026
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-4635
GO-2026-5820
GHSA-pg7c-462j-grxv
Jul 07, 2026
Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5755
GO-2026-5835
GHSA-37j2-3vv8-cf24
Jul 07, 2026
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-3636
GO-2026-5818
GHSA-ffpr-pfr4-g354
Jul 07, 2026
Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28735
GO-2026-5839
GHSA-r5vf-grcx-5vqp
Jul 07, 2026
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-28732
GO-2026-5726
GHSA-wvcv-9xpm-7mqc
Jun 25, 2026
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260306123948-f5fe8ded6b63. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6333
GO-2026-5671
GHSA-vqp5-2mrp-qqxg
Jun 25, 2026
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260325160634-e738016c5920. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6345
GO-2026-5727
GHSA-wvgv-4fc3-2rcp
Jun 25, 2026
Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260311102650-3057ae7e83e9. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3114
GO-2026-5663
GHSA-vhgh-g7x8-4rx8
Jun 25, 2026
Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3637
GO-2026-5651
GHSA-v549-xx3c-6pc8
Jun 25, 2026
Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260316171743-090408f09f53. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27659
GO-2026-5629
GHSA-rmhw-c3xr-m3xx
Jun 25, 2026
Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3115
GO-2026-5512
GHSA-mpc7-mm28-f6wq
Jun 25, 2026
Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6334
GO-2026-5474
GHSA-jp3f-x449-4q75
Jun 25, 2026
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260318173148-e9ae890a013b. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4273
GO-2026-5432
GHSA-hqpj-f3jh-29vx
Jun 25, 2026
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260313190740-742e0be95074. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3495
GO-2026-5484
GHSA-jx93-pf6x-874r
Jun 25, 2026
Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260310115442-5a1ea95044dc; github.com/mattermost/mattermost/server/v8 before v8.0.0-20260310115442-5a1ea95044d. Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-2325
GO-2026-5489
GHSA-m3p3-8frq-q7qh
Jun 25, 2026
Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6343
GO-2026-5494
GHSA-m79q-8qf5-v622
Jun 25, 2026
Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3590
GO-2026-5507
GHSA-mh4x-rmrx-3hp4
Jun 25, 2026
Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server Fixed in
10.11.13+incompatible
11.3.3+incompatible
11.4.3+incompatible
11.5.0+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4286
GO-2026-5404
GHSA-gvg4-jhmr-6j23
Jun 25, 2026
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks Fixed in
10.11.14+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6346
GO-2026-5293
GHSA-9p64-jpc7-m2rp
Jun 25, 2026
Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260326202606-fac92f4a71f3. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4274
GO-2026-5393
GHSA-g7fp-cqj5-x8hf
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4858
GO-2026-5311
GHSA-c4r7-j7pp-r8mp
Jun 25, 2026
Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server Fixed in
10.11.15+incompatible
11.4.5+incompatible
11.5.4+incompatible
11.6.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6340
GO-2026-5325
GHSA-cjm8-jxpw-g43m
Jun 25, 2026
Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260325191733-fb11968f8798. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-27656
GO-2026-5360
GHSA-fg35-5rf6-qg3g
Jun 25, 2026
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6347
GO-2026-5238
GHSA-82j6-4fq7-fx62
Jun 25, 2026
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20719
GO-2026-5245
GHSA-86vc-mg26-fj6x
Jun 25, 2026
Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server Fixed in
10.11.2+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-28759
GO-2026-5256
GHSA-8h9w-w78c-vvr3
Jun 25, 2026
Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260216150504-8738f8c4b3d4. Fixed in
10.11.14+incompatible
11.4.4+incompatible
11.5.2+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3112
GO-2026-5092
GHSA-3mw5-466q-295q
Jun 25, 2026
Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3113
GO-2026-5112
GHSA-4765-v66x-rqx7
Jun 25, 2026
Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20260105080200-d27a2195068d before v8.0.0-20260217110922-b7d4a1f1f59b. Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-3108
GO-2026-5067
GHSA-3439-vqgj-2gcf
Jun 25, 2026
Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-26233
GO-2026-4916
GHSA-247x-7qw8-fp98
Apr 02, 2026
Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20260105080200-d27a2195068d before v8.0.0-20260217110922-b7d4a1f1f59b. Fixed in
10.11.12+incompatible
11.2.4+incompatible
11.3.2+incompatible
11.4.1+incompatible
References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-2456
GO-2026-4726
GHSA-34g8-9fpp-46ch
Mar 26, 2026
Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127165411-fe3052073dc6. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-25783
GO-2026-4725
GHSA-2v3w-6g35-5f9v
Mar 26, 2026
Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129181235-1346cf529aef. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-22545
GO-2026-4786
GHSA-rv67-7w2g-7976
Mar 23, 2026
Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127144908-ced9a56e3988. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-4265
GO-2026-4749
GHSA-xpvf-6qcc-9jqc
Mar 23, 2026
Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107144005-c7f6efdfb035. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-21386
GO-2026-4744
GHSA-5mr9-crcg-8wh2
Mar 23, 2026
Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260130144323-5bb5261c72fa. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26246
GO-2026-4727
GHSA-44mv-jq72-gj49
Mar 23, 2026
Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260115183946-38b413a27604. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-24692
GO-2026-4745
GHSA-cwfj-642j-gfh4
Mar 23, 2026
Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107142155-0481bd1fb045. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2458
GO-2026-4729
GHSA-679f-wmrg-qf57
Mar 23, 2026
Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260113182106-a18b80ba4c32. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-24458
GO-2026-4731
GHSA-m5rv-56xx-hfc6
Mar 23, 2026
Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129164748-7201f42d955f. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2578
GO-2026-4734
GHSA-3rhr-jr63-hwq5
Mar 23, 2026
Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127062706-c6b205f0d770. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2455
GO-2026-4746
GHSA-gqv7-j2j8-qmwq
Mar 23, 2026
Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129133647-5d787969c2d5. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2457
GO-2026-4732
GHSA-ph22-fw5m-w2q9
Mar 23, 2026
Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123211116-9efe617be8b8. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25780
GO-2026-4733
GHSA-xv2p-wchj-qjhp
Mar 23, 2026
Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123215601-86797c508c44. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-2463
GO-2026-4735
GHSA-fx49-m253-27jj
Mar 23, 2026
Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260105134819-cc427af41b2a. Fixed in
10.11.11+incompatible
11.2.3+incompatible
11.3.1+incompatible
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-13767
GO-2025-4259
GHSA-fmqf-pmcm-8cx9
Feb 26, 2026
Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues in github.com/mattermost/mattermost-server Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20251121122154-b57c297c6d7. Fixed in
10.11.8+incompatible
10.12.4+incompatible
11.0.6+incompatible
11.1.1+incompatible
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-14435
GO-2026-4326
GHSA-mx8m-v8qm-xwr8
Feb 26, 2026
Mattermost is vulnerable to DoS due to infinite re-renders on API errors in github.com/mattermost/mattermost-server Mattermost is vulnerable to DoS due to infinite re-renders on API errors in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.11.9+incompatible
11.0.7+incompatible
11.1.2+incompatible
References
Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-64641
GO-2025-4260
GHSA-vww6-79rv-3j4x
Feb 26, 2026
Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin in github.com/mattermost/mattermost-server Mattermost doesn't verify that post actions invoking NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20251121122154-b57c297c6d7. Fixed in
10.11.8+incompatible
10.12.4+incompatible
11.0.6+incompatible
11.1.1+incompatible
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-14822
GO-2026-4325
GHSA-9r42-rhw3-2222
Feb 26, 2026
Mattermost is vulnerable to CPU exhaustion via crafted HTTP request in github.com/mattermost/mattermost-server Mattermost is vulnerable to CPU exhaustion via crafted HTTP request in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.11.9+incompatible
11.2.0+incompatible
References
Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-20796
GO-2026-4495
GHSA-2xf7-hmf6-p64j
Feb 23, 2026
Mattermost doesn't properly validate channel membership at the time of data retrieval in github.com/mattermost/mattermost-server Mattermost doesn't properly validate channel membership at the time of data retrieval in github.com/mattermost/mattermost-server Fixed in
10.11.10+incompatible
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-22892
GO-2026-4496
GHSA-9pj7-jh2r-87g8
Feb 23, 2026
Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts in github.com/mattermost/mattermost-server Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts in github.com/mattermost/mattermost-server Fixed in
10.11.10+incompatible
11.1.3+incompatible
11.2.2+incompatible
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13352
GO-2025-4247
GHSA-jf5h-xfw4-p8gp
Dec 22, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55074
GO-2025-4133
GHSA-9hh7-6558-qfp2
Nov 25, 2025
Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250905150616-ba86dfc5876b6. Fixed in
10.5.12+incompatible
10.11.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55073
GO-2025-4129
GHSA-ff85-qw3h-g9vp
Nov 18, 2025
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server Fixed in
10.5.12+incompatible
10.11.4+incompatible
10.12.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11794
GO-2025-4130
GHSA-mqp8-pgg5-7x7m
Nov 18, 2025
Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server Fixed in
10.5.12+incompatible
10.11.4+incompatible
10.12.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11777
GO-2025-4122
GHSA-mqcj-8c2g-h97q
Nov 17, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost Fixed in
10.5.12+incompatible
10.11.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-10545
GO-2025-4030
GHSA-424h-xj87-m937
Oct 30, 2025
Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.11+incompatible
10.11.3+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41410
GO-2025-4029
GHSA-3q4q-wqm6-hvf3
Oct 30, 2025
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250822083415-01b95392a450. Fixed in
10.5.11+incompatible
10.10.3+incompatible
10.11.3+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54499
GO-2025-4036
GHSA-xr3w-rmvj-f6m7
Oct 30, 2025
Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.11+incompatible
10.11.3+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-58075
GO-2025-4035
GHSA-r6qj-894f-5hr2
Oct 30, 2025
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250815100400-2d5cdc6e217e. Fixed in
10.5.11+incompatible
10.10.3+incompatible
10.11.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58073
GO-2025-4032
GHSA-6q7m-p8cc-998r
Oct 30, 2025
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.11+incompatible
10.10.3+incompatible
10.11.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.11.1+incompatible
minor
|
|
v10.7.5-rc4+incompatible
pre
46 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.7.5-rc4+incompatible
pre
|
|
v10.5.9-rc3+incompatible
pre
69 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55074
GO-2025-4133
GHSA-9hh7-6558-qfp2
Nov 25, 2025
Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250905150616-ba86dfc5876b6. Fixed in
10.5.12+incompatible
10.11.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55073
GO-2025-4129
GHSA-ff85-qw3h-g9vp
Nov 18, 2025
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server Fixed in
10.5.12+incompatible
10.11.4+incompatible
10.12.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11794
GO-2025-4130
GHSA-mqp8-pgg5-7x7m
Nov 18, 2025
Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server Fixed in
10.5.12+incompatible
10.11.4+incompatible
10.12.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11777
GO-2025-4122
GHSA-mqcj-8c2g-h97q
Nov 17, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost Fixed in
10.5.12+incompatible
10.11.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-10545
GO-2025-4030
GHSA-424h-xj87-m937
Oct 30, 2025
Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.11+incompatible
10.11.3+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41410
GO-2025-4029
GHSA-3q4q-wqm6-hvf3
Oct 30, 2025
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250822083415-01b95392a450. Fixed in
10.5.11+incompatible
10.10.3+incompatible
10.11.3+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54499
GO-2025-4036
GHSA-xr3w-rmvj-f6m7
Oct 30, 2025
Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.11+incompatible
10.11.3+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-58075
GO-2025-4035
GHSA-r6qj-894f-5hr2
Oct 30, 2025
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250815100400-2d5cdc6e217e. Fixed in
10.5.11+incompatible
10.10.3+incompatible
10.11.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58073
GO-2025-4032
GHSA-6q7m-p8cc-998r
Oct 30, 2025
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.11+incompatible
10.10.3+incompatible
10.11.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9081
GO-2025-3978
GHSA-f72g-52v7-mg3p
Sep 24, 2025
Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Fixed in
9.11.18+incompatible
10.5.9+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9079
GO-2025-3977
GHSA-qx3f-6vq3-8j8m
Sep 24, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9072
GO-2025-3958
GHSA-69j8-prx2-vx98
Sep 17, 2025
Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.10+incompatible
10.9.5+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9084
GO-2025-3960
GHSA-hm95-jx66-g2gh
Sep 17, 2025
Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-202508080704-39bd251fe4f600. Fixed in
10.5.10+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9078
GO-2025-3959
GHSA-9p92-x77w-9fw2
Sep 17, 2025
Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49810
GO-2025-3903
GHSA-pwvr-grqg-7vp2
Aug 29, 2025
Mattermost Lack of Access Control Validation in github.com/mattermost/mattermost-server Mattermost Lack of Access Control Validation in github.com/mattermost/mattermost-server Fixed in
10.5.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8402
GO-2025-3911
GHSA-h469-4fcf-p23h
Aug 29, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-53971
GO-2025-3902
GHSA-4276-cm8c-788h
Aug 29, 2025
Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49222
GO-2025-3904
GHSA-q453-638c-h4mr
Aug 29, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-36530
GO-2025-3901
GHSA-gq3r-5833-5532
Aug 29, 2025
Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250619095651-9dd0b3943e55. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47870
GO-2025-3905
GHSA-qj47-w9f2-qg44
Aug 29, 2025
Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47700
GO-2025-3906
GHSA-vqwh-5jhh-vc9p
Aug 29, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin in github.com/mattermost/mattermost-server Mattermost Server SSRF Vulnerability via the Agents Plugin in github.com/mattermost/mattermost-server Fixed in
10.5.10+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6465
GO-2025-3910
GHSA-pj6f-rc94-gw53
Aug 29, 2025
Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8023
GO-2025-3907
GHSA-x67c-v8jr-p29r
Aug 29, 2025
Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.5.9-rc3+incompatible
pre
|
|
v10.5.9-rc1+incompatible
pre
69 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55074
GO-2025-4133
GHSA-9hh7-6558-qfp2
Nov 25, 2025
Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250905150616-ba86dfc5876b6. Fixed in
10.5.12+incompatible
10.11.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55073
GO-2025-4129
GHSA-ff85-qw3h-g9vp
Nov 18, 2025
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server Fixed in
10.5.12+incompatible
10.11.4+incompatible
10.12.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11794
GO-2025-4130
GHSA-mqp8-pgg5-7x7m
Nov 18, 2025
Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server Fixed in
10.5.12+incompatible
10.11.4+incompatible
10.12.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11777
GO-2025-4122
GHSA-mqcj-8c2g-h97q
Nov 17, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost Fixed in
10.5.12+incompatible
10.11.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-10545
GO-2025-4030
GHSA-424h-xj87-m937
Oct 30, 2025
Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.11+incompatible
10.11.3+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41410
GO-2025-4029
GHSA-3q4q-wqm6-hvf3
Oct 30, 2025
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250822083415-01b95392a450. Fixed in
10.5.11+incompatible
10.10.3+incompatible
10.11.3+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54499
GO-2025-4036
GHSA-xr3w-rmvj-f6m7
Oct 30, 2025
Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.11+incompatible
10.11.3+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-58075
GO-2025-4035
GHSA-r6qj-894f-5hr2
Oct 30, 2025
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250815100400-2d5cdc6e217e. Fixed in
10.5.11+incompatible
10.10.3+incompatible
10.11.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-58073
GO-2025-4032
GHSA-6q7m-p8cc-998r
Oct 30, 2025
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.11+incompatible
10.10.3+incompatible
10.11.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9081
GO-2025-3978
GHSA-f72g-52v7-mg3p
Sep 24, 2025
Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Fixed in
9.11.18+incompatible
10.5.9+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9079
GO-2025-3977
GHSA-qx3f-6vq3-8j8m
Sep 24, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9072
GO-2025-3958
GHSA-69j8-prx2-vx98
Sep 17, 2025
Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server Fixed in
10.5.10+incompatible
10.9.5+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9084
GO-2025-3960
GHSA-hm95-jx66-g2gh
Sep 17, 2025
Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-202508080704-39bd251fe4f600. Fixed in
10.5.10+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9078
GO-2025-3959
GHSA-9p92-x77w-9fw2
Sep 17, 2025
Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49810
GO-2025-3903
GHSA-pwvr-grqg-7vp2
Aug 29, 2025
Mattermost Lack of Access Control Validation in github.com/mattermost/mattermost-server Mattermost Lack of Access Control Validation in github.com/mattermost/mattermost-server Fixed in
10.5.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8402
GO-2025-3911
GHSA-h469-4fcf-p23h
Aug 29, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-53971
GO-2025-3902
GHSA-4276-cm8c-788h
Aug 29, 2025
Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49222
GO-2025-3904
GHSA-q453-638c-h4mr
Aug 29, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-36530
GO-2025-3901
GHSA-gq3r-5833-5532
Aug 29, 2025
Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250619095651-9dd0b3943e55. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47870
GO-2025-3905
GHSA-qj47-w9f2-qg44
Aug 29, 2025
Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47700
GO-2025-3906
GHSA-vqwh-5jhh-vc9p
Aug 29, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin in github.com/mattermost/mattermost-server Mattermost Server SSRF Vulnerability via the Agents Plugin in github.com/mattermost/mattermost-server Fixed in
10.5.10+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6465
GO-2025-3910
GHSA-pj6f-rc94-gw53
Aug 29, 2025
Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8023
GO-2025-3907
GHSA-x67c-v8jr-p29r
Aug 29, 2025
Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.5.9-rc1+incompatible
pre
|
|
v10.7.5-rc1+incompatible
pre
46 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.7.5-rc1+incompatible
pre
|
|
v10.8.3+incompatible
minor
54 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9079
GO-2025-3977
GHSA-qx3f-6vq3-8j8m
Sep 24, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9078
GO-2025-3959
GHSA-9p92-x77w-9fw2
Sep 17, 2025
Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8402
GO-2025-3911
GHSA-h469-4fcf-p23h
Aug 29, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49222
GO-2025-3904
GHSA-q453-638c-h4mr
Aug 29, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-36530
GO-2025-3901
GHSA-gq3r-5833-5532
Aug 29, 2025
Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250619095651-9dd0b3943e55. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47870
GO-2025-3905
GHSA-qj47-w9f2-qg44
Aug 29, 2025
Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6465
GO-2025-3910
GHSA-pj6f-rc94-gw53
Aug 29, 2025
Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8023
GO-2025-3907
GHSA-x67c-v8jr-p29r
Aug 29, 2025
Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.8.3+incompatible
minor
|
|
v10.7.3-rc1+incompatible
pre
53 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6233
GO-2025-3820
GHSA-wvw2-3jh4-4c39
Jul 29, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.8+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6226
GO-2025-3819
GHSA-7h34-9chr-58qh
Jul 29, 2025
Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.7+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47871
GO-2025-3797
GHSA-wgvp-jj4w-88hf
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-46702
GO-2025-3796
GHSA-v8fr-vxmw-6mf6
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3227
GO-2025-3772
GHSA-qwwm-c582-82rx
Jul 28, 2025
Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4981
GO-2025-3769
GHSA-qh58-9v3j-wcjc
Jul 28, 2025
Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250519205859-65aec10162f6
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3228
GO-2025-3771
GHSA-4578-6gjh-f2jm
Jul 28, 2025
Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.7.3-rc1+incompatible
pre
|
|
v10.4.5+incompatible
patch
50 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.4.5+incompatible
patch
|
|
v9.11.11+incompatible
minor
75 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9081
GO-2025-3978
GHSA-f72g-52v7-mg3p
Sep 24, 2025
Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Fixed in
9.11.18+incompatible
10.5.9+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9079
GO-2025-3977
GHSA-qx3f-6vq3-8j8m
Sep 24, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9078
GO-2025-3959
GHSA-9p92-x77w-9fw2
Sep 17, 2025
Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8402
GO-2025-3911
GHSA-h469-4fcf-p23h
Aug 29, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-53971
GO-2025-3902
GHSA-4276-cm8c-788h
Aug 29, 2025
Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49222
GO-2025-3904
GHSA-q453-638c-h4mr
Aug 29, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-36530
GO-2025-3901
GHSA-gq3r-5833-5532
Aug 29, 2025
Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250619095651-9dd0b3943e55. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47870
GO-2025-3905
GHSA-qj47-w9f2-qg44
Aug 29, 2025
Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8023
GO-2025-3907
GHSA-x67c-v8jr-p29r
Aug 29, 2025
Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6233
GO-2025-3820
GHSA-wvw2-3jh4-4c39
Jul 29, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.8+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6227
GO-2025-3818
GHSA-4fwj-8595-wp25
Jul 29, 2025
Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.8+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6226
GO-2025-3819
GHSA-7h34-9chr-58qh
Jul 29, 2025
Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.7+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47871
GO-2025-3797
GHSA-wgvp-jj4w-88hf
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-46702
GO-2025-3796
GHSA-v8fr-vxmw-6mf6
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3227
GO-2025-3772
GHSA-qwwm-c582-82rx
Jul 28, 2025
Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4981
GO-2025-3769
GHSA-qh58-9v3j-wcjc
Jul 28, 2025
Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250519205859-65aec10162f6
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3228
GO-2025-3771
GHSA-4578-6gjh-f2jm
Jul 28, 2025
Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4128
GO-2025-3757
GHSA-jwhw-xf5v-qgxc
Jun 11, 2025
Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server Fixed in
9.11.14+incompatible
10.5.5+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4573
GO-2025-3756
GHSA-4r67-4x4p-fprg
Jun 11, 2025
Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server Fixed in
9.11.14+incompatible
10.5.5+incompatible
10.6.4+incompatible
10.7.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-31947
GO-2025-3692
GHSA-qgwx-rffp-6cx9
May 23, 2025
Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-2570
GO-2025-3694
GHSA-fpff-wj6m-grvr
May 23, 2025
Mattermost Fails to Check User Access to `ExperimentalSettings` in github.com/mattermost/mattermost-server Mattermost Fails to Check User Access to Fixed in
9.11.12+incompatible
10.5.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-2527
GO-2025-3691
GHSA-h356-3mfw-x368
May 23, 2025
Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.5.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3446
GO-2025-3693
GHSA-r7r2-m3vr-c8qc
May 23, 2025
Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.11.11+incompatible
minor
|
|
v9.11.10-rc1+incompatible
pre
83 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9081
GO-2025-3978
GHSA-f72g-52v7-mg3p
Sep 24, 2025
Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Fixed in
9.11.18+incompatible
10.5.9+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9079
GO-2025-3977
GHSA-qx3f-6vq3-8j8m
Sep 24, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9078
GO-2025-3959
GHSA-9p92-x77w-9fw2
Sep 17, 2025
Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8402
GO-2025-3911
GHSA-h469-4fcf-p23h
Aug 29, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-53971
GO-2025-3902
GHSA-4276-cm8c-788h
Aug 29, 2025
Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49222
GO-2025-3904
GHSA-q453-638c-h4mr
Aug 29, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-36530
GO-2025-3901
GHSA-gq3r-5833-5532
Aug 29, 2025
Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250619095651-9dd0b3943e55. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47870
GO-2025-3905
GHSA-qj47-w9f2-qg44
Aug 29, 2025
Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8023
GO-2025-3907
GHSA-x67c-v8jr-p29r
Aug 29, 2025
Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6233
GO-2025-3820
GHSA-wvw2-3jh4-4c39
Jul 29, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.8+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6227
GO-2025-3818
GHSA-4fwj-8595-wp25
Jul 29, 2025
Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.8+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6226
GO-2025-3819
GHSA-7h34-9chr-58qh
Jul 29, 2025
Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.7+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47871
GO-2025-3797
GHSA-wgvp-jj4w-88hf
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-46702
GO-2025-3796
GHSA-v8fr-vxmw-6mf6
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3227
GO-2025-3772
GHSA-qwwm-c582-82rx
Jul 28, 2025
Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4981
GO-2025-3769
GHSA-qh58-9v3j-wcjc
Jul 28, 2025
Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250519205859-65aec10162f6
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3228
GO-2025-3771
GHSA-4578-6gjh-f2jm
Jul 28, 2025
Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4128
GO-2025-3757
GHSA-jwhw-xf5v-qgxc
Jun 11, 2025
Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server Fixed in
9.11.14+incompatible
10.5.5+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4573
GO-2025-3756
GHSA-4r67-4x4p-fprg
Jun 11, 2025
Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server Fixed in
9.11.14+incompatible
10.5.5+incompatible
10.6.4+incompatible
10.7.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-31947
GO-2025-3692
GHSA-qgwx-rffp-6cx9
May 23, 2025
Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-2570
GO-2025-3694
GHSA-fpff-wj6m-grvr
May 23, 2025
Mattermost Fails to Check User Access to `ExperimentalSettings` in github.com/mattermost/mattermost-server Mattermost Fails to Check User Access to Fixed in
9.11.12+incompatible
10.5.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-2527
GO-2025-3691
GHSA-h356-3mfw-x368
May 23, 2025
Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.5.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3446
GO-2025-3693
GHSA-r7r2-m3vr-c8qc
May 23, 2025
Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2564
GO-2025-3623
GHSA-mj2p-v2c2-vh4v
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27571
GO-2025-3619
GHSA-h4rr-f37j-4hh7
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2475
GO-2025-3610
GHSA-6rqh-8465-2xcw
Apr 22, 2025
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-server Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24839
GO-2025-3621
GHSA-j639-m367-75cf
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2424
GO-2025-3611
GHSA-wwhj-pw6h-f8hw
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-31363
GO-2025-3622
GHSA-9h6j-4ffx-cm84
Apr 22, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27538
GO-2025-3620
GHSA-j5jw-m2ph-3jjf
Apr 22, 2025
Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32093
GO-2025-3609
GHSA-322v-vh2g-qvpv
Apr 22, 2025
Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.11.10-rc1+incompatible
pre
|
|
v10.4.3-rc3+incompatible
pre
62 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-31947
GO-2025-3692
GHSA-qgwx-rffp-6cx9
May 23, 2025
Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3446
GO-2025-3693
GHSA-r7r2-m3vr-c8qc
May 23, 2025
Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2564
GO-2025-3623
GHSA-mj2p-v2c2-vh4v
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27571
GO-2025-3619
GHSA-h4rr-f37j-4hh7
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24839
GO-2025-3621
GHSA-j639-m367-75cf
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-31363
GO-2025-3622
GHSA-9h6j-4ffx-cm84
Apr 22, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32093
GO-2025-3609
GHSA-322v-vh2g-qvpv
Apr 22, 2025
Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27933
GO-2025-3556
BIT-mattermost-2025-27933
GHSA-h5v9-xw2g-7hrq
Mar 25, 2025
Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25274
GO-2025-3550
BIT-mattermost-2025-25274
GHSA-4v65-xqcj-wpgg
Mar 25, 2025
Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-24920
GO-2025-3552
BIT-mattermost-2025-24920
GHSA-rp74-x43m-cpw3
Mar 25, 2025
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-25068
GO-2025-3551
BIT-mattermost-2025-25068
GHSA-72qv-j8vr-xvfv
Mar 25, 2025
Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-30179
GO-2025-3549
BIT-mattermost-2025-30179
GHSA-3gpx-p63p-pr5r
Mar 25, 2025
Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.4.3-rc3+incompatible
pre
|
|
v10.4.2+incompatible
minor
62 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-31947
GO-2025-3692
GHSA-qgwx-rffp-6cx9
May 23, 2025
Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3446
GO-2025-3693
GHSA-r7r2-m3vr-c8qc
May 23, 2025
Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2564
GO-2025-3623
GHSA-mj2p-v2c2-vh4v
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27571
GO-2025-3619
GHSA-h4rr-f37j-4hh7
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24839
GO-2025-3621
GHSA-j639-m367-75cf
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-31363
GO-2025-3622
GHSA-9h6j-4ffx-cm84
Apr 22, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32093
GO-2025-3609
GHSA-322v-vh2g-qvpv
Apr 22, 2025
Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27933
GO-2025-3556
BIT-mattermost-2025-27933
GHSA-h5v9-xw2g-7hrq
Mar 25, 2025
Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25274
GO-2025-3550
BIT-mattermost-2025-25274
GHSA-4v65-xqcj-wpgg
Mar 25, 2025
Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-24920
GO-2025-3552
BIT-mattermost-2025-24920
GHSA-rp74-x43m-cpw3
Mar 25, 2025
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-25068
GO-2025-3551
BIT-mattermost-2025-25068
GHSA-72qv-j8vr-xvfv
Mar 25, 2025
Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-30179
GO-2025-3549
BIT-mattermost-2025-30179
GHSA-3gpx-p63p-pr5r
Mar 25, 2025
Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.4.2+incompatible
minor
|
|
v9.11.6-rc2+incompatible
pre
99 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9081
GO-2025-3978
GHSA-f72g-52v7-mg3p
Sep 24, 2025
Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Fixed in
9.11.18+incompatible
10.5.9+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9079
GO-2025-3977
GHSA-qx3f-6vq3-8j8m
Sep 24, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9078
GO-2025-3959
GHSA-9p92-x77w-9fw2
Sep 17, 2025
Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8402
GO-2025-3911
GHSA-h469-4fcf-p23h
Aug 29, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-53971
GO-2025-3902
GHSA-4276-cm8c-788h
Aug 29, 2025
Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49222
GO-2025-3904
GHSA-q453-638c-h4mr
Aug 29, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-36530
GO-2025-3901
GHSA-gq3r-5833-5532
Aug 29, 2025
Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250619095651-9dd0b3943e55. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47870
GO-2025-3905
GHSA-qj47-w9f2-qg44
Aug 29, 2025
Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8023
GO-2025-3907
GHSA-x67c-v8jr-p29r
Aug 29, 2025
Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6233
GO-2025-3820
GHSA-wvw2-3jh4-4c39
Jul 29, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.8+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6227
GO-2025-3818
GHSA-4fwj-8595-wp25
Jul 29, 2025
Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.8+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6226
GO-2025-3819
GHSA-7h34-9chr-58qh
Jul 29, 2025
Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.7+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47871
GO-2025-3797
GHSA-wgvp-jj4w-88hf
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-46702
GO-2025-3796
GHSA-v8fr-vxmw-6mf6
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3227
GO-2025-3772
GHSA-qwwm-c582-82rx
Jul 28, 2025
Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4981
GO-2025-3769
GHSA-qh58-9v3j-wcjc
Jul 28, 2025
Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250519205859-65aec10162f6
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3228
GO-2025-3771
GHSA-4578-6gjh-f2jm
Jul 28, 2025
Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4128
GO-2025-3757
GHSA-jwhw-xf5v-qgxc
Jun 11, 2025
Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server Fixed in
9.11.14+incompatible
10.5.5+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4573
GO-2025-3756
GHSA-4r67-4x4p-fprg
Jun 11, 2025
Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server Fixed in
9.11.14+incompatible
10.5.5+incompatible
10.6.4+incompatible
10.7.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-31947
GO-2025-3692
GHSA-qgwx-rffp-6cx9
May 23, 2025
Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-2570
GO-2025-3694
GHSA-fpff-wj6m-grvr
May 23, 2025
Mattermost Fails to Check User Access to `ExperimentalSettings` in github.com/mattermost/mattermost-server Mattermost Fails to Check User Access to Fixed in
9.11.12+incompatible
10.5.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-2527
GO-2025-3691
GHSA-h356-3mfw-x368
May 23, 2025
Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.5.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3446
GO-2025-3693
GHSA-r7r2-m3vr-c8qc
May 23, 2025
Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2564
GO-2025-3623
GHSA-mj2p-v2c2-vh4v
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27571
GO-2025-3619
GHSA-h4rr-f37j-4hh7
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2475
GO-2025-3610
GHSA-6rqh-8465-2xcw
Apr 22, 2025
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-server Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24866
GO-2025-3604
GHSA-xfq9-hh5x-xfq9
Apr 22, 2025
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint in github.com/mattermost/mattermost-server Mattermost Fails to Enforce Proper Access Controls on Fixed in
9.11.9+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24839
GO-2025-3621
GHSA-j639-m367-75cf
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2424
GO-2025-3611
GHSA-wwhj-pw6h-f8hw
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-31363
GO-2025-3622
GHSA-9h6j-4ffx-cm84
Apr 22, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27538
GO-2025-3620
GHSA-j5jw-m2ph-3jjf
Apr 22, 2025
Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32093
GO-2025-3609
GHSA-322v-vh2g-qvpv
Apr 22, 2025
Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27933
GO-2025-3556
BIT-mattermost-2025-27933
GHSA-h5v9-xw2g-7hrq
Mar 25, 2025
Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25274
GO-2025-3550
BIT-mattermost-2025-25274
GHSA-4v65-xqcj-wpgg
Mar 25, 2025
Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1472
GO-2025-3534
GHSA-fqrq-xmxj-v47x
Mar 25, 2025
Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-24920
GO-2025-3552
BIT-mattermost-2025-24920
GHSA-rp74-x43m-cpw3
Mar 25, 2025
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-25068
GO-2025-3551
BIT-mattermost-2025-25068
GHSA-72qv-j8vr-xvfv
Mar 25, 2025
Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27715
GO-2025-3555
BIT-mattermost-2025-27715
GHSA-cw7q-5cgc-h3h9
Mar 25, 2025
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel in github.com/mattermost/mattermost-server Mattermost fail to prompt for explicit approval before adding a team admin to a private channel in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-30179
GO-2025-3549
BIT-mattermost-2025-30179
GHSA-3gpx-p63p-pr5r
Mar 25, 2025
Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1412
GO-2025-3482
GHSA-rhvr-6w8c-6v7w
Mar 03, 2025
Mattermost fails to invalidate all active sessions when converting a user to a bot in github.com/mattermost/mattermost-server Mattermost fails to invalidate all active sessions when converting a user to a bot in github.com/mattermost/mattermost-server Fixed in
9.11.7+incompatible
10.4.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25279
GO-2025-3480
GHSA-5fwx-p6xh-vjrh
Mar 03, 2025
Mattermost allows reading arbitrary files related to importing boards in github.com/mattermost/mattermost-server Mattermost allows reading arbitrary files related to importing boards in github.com/mattermost/mattermost-server Fixed in
9.11.8+incompatible
10.2.3+incompatible
10.3.3+incompatible
10.4.2+incompatible
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24526
GO-2025-3481
GHSA-q8p2-2hwc-jw64
Mar 03, 2025
Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server Fixed in
9.11.8+incompatible
10.2.3+incompatible
10.3.3+incompatible
10.4.2+incompatible
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20051
GO-2025-3483
GHSA-v469-7wp6-7cvp
Mar 03, 2025
Mattermost allows reading arbitrary files in github.com/mattermost/mattermost-server Mattermost allows reading arbitrary files in github.com/mattermost/mattermost-server Fixed in
9.11.8+incompatible
10.2.3+incompatible
10.3.3+incompatible
10.4.2+incompatible
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20621
GO-2025-3407
GHSA-w6xh-c82w-h997
Jan 17, 2025
Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20088
GO-2025-3394
GHSA-45v9-w9fh-33j6
Jan 16, 2025
Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-21088
GO-2025-3393
GHSA-8j3q-gc9x-7972
Jan 16, 2025
Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20086
GO-2025-3392
GHSA-5m7j-6gc4-ff5g
Jan 16, 2025
Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.11.6-rc2+incompatible
pre
|
|
v9.11.6-rc1+incompatible
pre
99 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9081
GO-2025-3978
GHSA-f72g-52v7-mg3p
Sep 24, 2025
Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Fixed in
9.11.18+incompatible
10.5.9+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9079
GO-2025-3977
GHSA-qx3f-6vq3-8j8m
Sep 24, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-9078
GO-2025-3959
GHSA-9p92-x77w-9fw2
Sep 17, 2025
Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8402
GO-2025-3911
GHSA-h469-4fcf-p23h
Aug 29, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.4+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-53971
GO-2025-3902
GHSA-4276-cm8c-788h
Aug 29, 2025
Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49222
GO-2025-3904
GHSA-q453-638c-h4mr
Aug 29, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
10.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-36530
GO-2025-3901
GHSA-gq3r-5833-5532
Aug 29, 2025
Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250619095651-9dd0b3943e55. Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47870
GO-2025-3905
GHSA-qj47-w9f2-qg44
Aug 29, 2025
Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-8023
GO-2025-3907
GHSA-x67c-v8jr-p29r
Aug 29, 2025
Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Fixed in
9.11.18+incompatible
10.5.9+incompatible
10.8.4+incompatible
10.9.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6233
GO-2025-3820
GHSA-wvw2-3jh4-4c39
Jul 29, 2025
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.8+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6227
GO-2025-3818
GHSA-4fwj-8595-wp25
Jul 29, 2025
Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.8+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-6226
GO-2025-3819
GHSA-7h34-9chr-58qh
Jul 29, 2025
Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Fixed in
9.11.17+incompatible
10.5.7+incompatible
10.7.4+incompatible
10.8.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47871
GO-2025-3797
GHSA-wgvp-jj4w-88hf
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-46702
GO-2025-3796
GHSA-v8fr-vxmw-6mf6
Jul 28, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250513065225-4ae5d647fb88
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3227
GO-2025-3772
GHSA-qwwm-c582-82rx
Jul 28, 2025
Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4981
GO-2025-3769
GHSA-qh58-9v3j-wcjc
Jul 28, 2025
Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250519205859-65aec10162f6
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3228
GO-2025-3771
GHSA-4578-6gjh-f2jm
Jul 28, 2025
Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Fixed in
0.0.0-20250520060012-d0380305ef7a
9.11.16+incompatible
10.5.6+incompatible
10.6.6+incompatible
10.7.3+incompatible
10.8.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4128
GO-2025-3757
GHSA-jwhw-xf5v-qgxc
Jun 11, 2025
Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server Fixed in
9.11.14+incompatible
10.5.5+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4573
GO-2025-3756
GHSA-4r67-4x4p-fprg
Jun 11, 2025
Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server Fixed in
9.11.14+incompatible
10.5.5+incompatible
10.6.4+incompatible
10.7.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-31947
GO-2025-3692
GHSA-qgwx-rffp-6cx9
May 23, 2025
Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-2570
GO-2025-3694
GHSA-fpff-wj6m-grvr
May 23, 2025
Mattermost Fails to Check User Access to `ExperimentalSettings` in github.com/mattermost/mattermost-server Mattermost Fails to Check User Access to Fixed in
9.11.12+incompatible
10.5.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-2527
GO-2025-3691
GHSA-h356-3mfw-x368
May 23, 2025
Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.5.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3446
GO-2025-3693
GHSA-r7r2-m3vr-c8qc
May 23, 2025
Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Fixed in
9.11.12+incompatible
10.4.5+incompatible
10.5.3+incompatible
10.6.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2564
GO-2025-3623
GHSA-mj2p-v2c2-vh4v
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27571
GO-2025-3619
GHSA-h4rr-f37j-4hh7
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2475
GO-2025-3610
GHSA-6rqh-8465-2xcw
Apr 22, 2025
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-server Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24866
GO-2025-3604
GHSA-xfq9-hh5x-xfq9
Apr 22, 2025
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint in github.com/mattermost/mattermost-server Mattermost Fails to Enforce Proper Access Controls on Fixed in
9.11.9+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24839
GO-2025-3621
GHSA-j639-m367-75cf
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-2424
GO-2025-3611
GHSA-wwhj-pw6h-f8hw
Apr 22, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-31363
GO-2025-3622
GHSA-9h6j-4ffx-cm84
Apr 22, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27538
GO-2025-3620
GHSA-j5jw-m2ph-3jjf
Apr 22, 2025
Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32093
GO-2025-3609
GHSA-322v-vh2g-qvpv
Apr 22, 2025
Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Fixed in
9.11.10+incompatible
10.4.4+incompatible
10.5.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-27933
GO-2025-3556
BIT-mattermost-2025-27933
GHSA-h5v9-xw2g-7hrq
Mar 25, 2025
Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25274
GO-2025-3550
BIT-mattermost-2025-25274
GHSA-4v65-xqcj-wpgg
Mar 25, 2025
Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1472
GO-2025-3534
GHSA-fqrq-xmxj-v47x
Mar 25, 2025
Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-24920
GO-2025-3552
BIT-mattermost-2025-24920
GHSA-rp74-x43m-cpw3
Mar 25, 2025
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-25068
GO-2025-3551
BIT-mattermost-2025-25068
GHSA-72qv-j8vr-xvfv
Mar 25, 2025
Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27715
GO-2025-3555
BIT-mattermost-2025-27715
GHSA-cw7q-5cgc-h3h9
Mar 25, 2025
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel in github.com/mattermost/mattermost-server Mattermost fail to prompt for explicit approval before adding a team admin to a private channel in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-30179
GO-2025-3549
BIT-mattermost-2025-30179
GHSA-3gpx-p63p-pr5r
Mar 25, 2025
Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server Fixed in
9.11.9+incompatible
10.3.4+incompatible
10.4.3+incompatible
10.5.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1412
GO-2025-3482
GHSA-rhvr-6w8c-6v7w
Mar 03, 2025
Mattermost fails to invalidate all active sessions when converting a user to a bot in github.com/mattermost/mattermost-server Mattermost fails to invalidate all active sessions when converting a user to a bot in github.com/mattermost/mattermost-server Fixed in
9.11.7+incompatible
10.4.2+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25279
GO-2025-3480
GHSA-5fwx-p6xh-vjrh
Mar 03, 2025
Mattermost allows reading arbitrary files related to importing boards in github.com/mattermost/mattermost-server Mattermost allows reading arbitrary files related to importing boards in github.com/mattermost/mattermost-server Fixed in
9.11.8+incompatible
10.2.3+incompatible
10.3.3+incompatible
10.4.2+incompatible
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24526
GO-2025-3481
GHSA-q8p2-2hwc-jw64
Mar 03, 2025
Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server Fixed in
9.11.8+incompatible
10.2.3+incompatible
10.3.3+incompatible
10.4.2+incompatible
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20051
GO-2025-3483
GHSA-v469-7wp6-7cvp
Mar 03, 2025
Mattermost allows reading arbitrary files in github.com/mattermost/mattermost-server Mattermost allows reading arbitrary files in github.com/mattermost/mattermost-server Fixed in
9.11.8+incompatible
10.2.3+incompatible
10.3.3+incompatible
10.4.2+incompatible
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20621
GO-2025-3407
GHSA-w6xh-c82w-h997
Jan 17, 2025
Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20088
GO-2025-3394
GHSA-45v9-w9fh-33j6
Jan 16, 2025
Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-21088
GO-2025-3393
GHSA-8j3q-gc9x-7972
Jan 16, 2025
Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20086
GO-2025-3392
GHSA-5m7j-6gc4-ff5g
Jan 16, 2025
Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.11.6-rc1+incompatible
pre
|
|
v10.0.2+incompatible
major
59 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20621
GO-2025-3407
GHSA-w6xh-c82w-h997
Jan 17, 2025
Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20088
GO-2025-3394
GHSA-45v9-w9fh-33j6
Jan 16, 2025
Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-21088
GO-2025-3393
GHSA-8j3q-gc9x-7972
Jan 16, 2025
Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20086
GO-2025-3392
GHSA-5m7j-6gc4-ff5g
Jan 16, 2025
Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20033
GO-2025-3379
GHSA-2549-xh72-qrpm
Jan 09, 2025
Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v9.11.0 before v9.11.16. Fixed in
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-48872
GO-2024-3338
GHSA-826h-p4c3-477p
Dec 18, 2024
Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54682
GO-2024-3340
GHSA-v647-h8jj-fw5r
Dec 18, 2024
Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54083
GO-2024-3337
GHSA-69pr-78gv-7c6h
Dec 18, 2024
Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.0.2+incompatible
major
|
|
v10.1.2-rc1+incompatible
pre
59 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20621
GO-2025-3407
GHSA-w6xh-c82w-h997
Jan 17, 2025
Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20088
GO-2025-3394
GHSA-45v9-w9fh-33j6
Jan 16, 2025
Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-21088
GO-2025-3393
GHSA-8j3q-gc9x-7972
Jan 16, 2025
Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20086
GO-2025-3392
GHSA-5m7j-6gc4-ff5g
Jan 16, 2025
Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Fixed in
9.11.6+incompatible
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-20033
GO-2025-3379
GHSA-2549-xh72-qrpm
Jan 09, 2025
Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v9.11.0 before v9.11.16. Fixed in
10.0.4+incompatible
10.1.4+incompatible
10.2.1+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-48872
GO-2024-3338
GHSA-826h-p4c3-477p
Dec 18, 2024
Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54682
GO-2024-3340
GHSA-v647-h8jj-fw5r
Dec 18, 2024
Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54083
GO-2024-3337
GHSA-69pr-78gv-7c6h
Dec 18, 2024
Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.1.2-rc1+incompatible
pre
|
|
v10.0.0-rc4+incompatible
pre
51 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-35965
GO-2025-3643
GHSA-689c-xq7x-xjwf
Apr 24, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41395
GO-2025-3642
GHSA-3g36-gf7c-75qw
Apr 24, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-41423
GO-2025-3644
GHSA-fr22-5377-f3p7
Apr 24, 2025
Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-22449
GO-2025-3377
GHSA-q8fg-cp3q-5jwm
Jan 09, 2025
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v10.0.0-rc4+incompatible
pre
|
|
v9.9.2-rc2+incompatible
pre
54 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-40886
GO-2024-3097
GHSA-hrf9-rm95-fpf3
Aug 30, 2024
Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43780
GO-2024-3089
BIT-mattermost-2024-43780
GHSA-2jhx-w3vc-w59g
Aug 30, 2024
Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-8071
GO-2024-3094
GHSA-5263-pm2h-m7hw
Aug 30, 2024
Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32939
GO-2024-3093
GHSA-4ww8-fprq-cq34
Aug 30, 2024
Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39836
GO-2024-3096
GHSA-c6vp-jjgv-38wj
Aug 30, 2024
Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-42497
GO-2024-3091
BIT-mattermost-2024-42497
GHSA-fxq9-6946-34q7
Aug 30, 2024
Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.9.2-rc2+incompatible
pre
|
|
v9.5.8-rc1+incompatible
pre
58 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-48872
GO-2024-3338
GHSA-826h-p4c3-477p
Dec 18, 2024
Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54682
GO-2024-3340
GHSA-v647-h8jj-fw5r
Dec 18, 2024
Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54083
GO-2024-3337
GHSA-69pr-78gv-7c6h
Dec 18, 2024
Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-40886
GO-2024-3097
GHSA-hrf9-rm95-fpf3
Aug 30, 2024
Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40884
GO-2024-3090
BIT-mattermost-2024-40884
GHSA-3j95-8g47-fpwh
Aug 30, 2024
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43780
GO-2024-3089
BIT-mattermost-2024-43780
GHSA-2jhx-w3vc-w59g
Aug 30, 2024
Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-8071
GO-2024-3094
GHSA-5263-pm2h-m7hw
Aug 30, 2024
Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32939
GO-2024-3093
GHSA-4ww8-fprq-cq34
Aug 30, 2024
Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39836
GO-2024-3096
GHSA-c6vp-jjgv-38wj
Aug 30, 2024
Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-42497
GO-2024-3091
BIT-mattermost-2024-42497
GHSA-fxq9-6946-34q7
Aug 30, 2024
Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.5.8-rc1+incompatible
pre
|
|
v9.8.2+incompatible
minor
54 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-40886
GO-2024-3097
GHSA-hrf9-rm95-fpf3
Aug 30, 2024
Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43780
GO-2024-3089
BIT-mattermost-2024-43780
GHSA-2jhx-w3vc-w59g
Aug 30, 2024
Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-8071
GO-2024-3094
GHSA-5263-pm2h-m7hw
Aug 30, 2024
Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32939
GO-2024-3093
GHSA-4ww8-fprq-cq34
Aug 30, 2024
Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39836
GO-2024-3096
GHSA-c6vp-jjgv-38wj
Aug 30, 2024
Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-42497
GO-2024-3091
BIT-mattermost-2024-42497
GHSA-fxq9-6946-34q7
Aug 30, 2024
Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.8.2+incompatible
minor
|
|
v9.7.6-rc3+incompatible
pre
55 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39777
GO-2024-3092
GHSA-q22q-2rrf-m27p
Aug 30, 2024
Mattermost allows unsolicited invites to expose access to local channels in github.com/mattermost/mattermost-server Mattermost allows unsolicited invites to expose access to local channels in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.1+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39832
GO-2024-3020
GHSA-762m-4cx6-6mf4
Aug 06, 2024
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39839
GO-2024-3024
BIT-mattermost-2024-39839
GHSA-vg6q-84p8-qvqh
Aug 06, 2024
Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-36492
GO-2024-3025
GHSA-56mc-f9w7-2wxq
Aug 06, 2024
Mattermost failed to disallow the modification of local users when syncing users in shared channels in github.com/mattermost/mattermost-server Mattermost failed to disallow the modification of local users when syncing users in shared channels in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41162
GO-2024-3031
BIT-mattermost-2024-41162
GHSA-jr9x-3x7m-4j75
Aug 06, 2024
Mattermost allows a remote actor to make an arbitrary local channel read-only in github.com/mattermost/mattermost-server Mattermost allows a remote actor to make an arbitrary local channel read-only in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39274
GO-2024-3028
GHSA-cmc8-222c-vqp9
Aug 06, 2024
Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel in github.com/mattermost/mattermost-server Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41144
GO-2024-3023
BIT-mattermost-2024-41144
GHSA-vg67-chm7-8m3j
Aug 06, 2024
Mattermost allows remote actor to create/update/delete posts in arbitrary channels in github.com/mattermost/mattermost-server Mattermost allows remote actor to create/update/delete posts in arbitrary channels in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.7.6-rc3+incompatible
pre
|
|
v9.7.5-rc2+incompatible
pre
55 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39777
GO-2024-3092
GHSA-q22q-2rrf-m27p
Aug 30, 2024
Mattermost allows unsolicited invites to expose access to local channels in github.com/mattermost/mattermost-server Mattermost allows unsolicited invites to expose access to local channels in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.1+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39832
GO-2024-3020
GHSA-762m-4cx6-6mf4
Aug 06, 2024
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39839
GO-2024-3024
BIT-mattermost-2024-39839
GHSA-vg6q-84p8-qvqh
Aug 06, 2024
Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-36492
GO-2024-3025
GHSA-56mc-f9w7-2wxq
Aug 06, 2024
Mattermost failed to disallow the modification of local users when syncing users in shared channels in github.com/mattermost/mattermost-server Mattermost failed to disallow the modification of local users when syncing users in shared channels in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41162
GO-2024-3031
BIT-mattermost-2024-41162
GHSA-jr9x-3x7m-4j75
Aug 06, 2024
Mattermost allows a remote actor to make an arbitrary local channel read-only in github.com/mattermost/mattermost-server Mattermost allows a remote actor to make an arbitrary local channel read-only in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39274
GO-2024-3028
GHSA-cmc8-222c-vqp9
Aug 06, 2024
Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel in github.com/mattermost/mattermost-server Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41144
GO-2024-3023
BIT-mattermost-2024-41144
GHSA-vg67-chm7-8m3j
Aug 06, 2024
Mattermost allows remote actor to create/update/delete posts in arbitrary channels in github.com/mattermost/mattermost-server Mattermost allows remote actor to create/update/delete posts in arbitrary channels in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.7.5-rc2+incompatible
pre
|
|
v9.5.5-rc1+incompatible
pre
68 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-48872
GO-2024-3338
GHSA-826h-p4c3-477p
Dec 18, 2024
Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54682
GO-2024-3340
GHSA-v647-h8jj-fw5r
Dec 18, 2024
Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54083
GO-2024-3337
GHSA-69pr-78gv-7c6h
Dec 18, 2024
Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.13+incompatible
9.11.5+incompatible
10.0.3+incompatible
10.1.3+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-40886
GO-2024-3097
GHSA-hrf9-rm95-fpf3
Aug 30, 2024
Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40884
GO-2024-3090
BIT-mattermost-2024-40884
GHSA-3j95-8g47-fpwh
Aug 30, 2024
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43780
GO-2024-3089
BIT-mattermost-2024-43780
GHSA-2jhx-w3vc-w59g
Aug 30, 2024
Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-8071
GO-2024-3094
GHSA-5263-pm2h-m7hw
Aug 30, 2024
Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32939
GO-2024-3093
GHSA-4ww8-fprq-cq34
Aug 30, 2024
Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39836
GO-2024-3096
GHSA-c6vp-jjgv-38wj
Aug 30, 2024
Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-42497
GO-2024-3091
BIT-mattermost-2024-42497
GHSA-fxq9-6946-34q7
Aug 30, 2024
Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server Fixed in
9.5.8+incompatible
9.8.3+incompatible
9.9.2+incompatible
9.10.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39777
GO-2024-3092
GHSA-q22q-2rrf-m27p
Aug 30, 2024
Mattermost allows unsolicited invites to expose access to local channels in github.com/mattermost/mattermost-server Mattermost allows unsolicited invites to expose access to local channels in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.1+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39832
GO-2024-3020
GHSA-762m-4cx6-6mf4
Aug 06, 2024
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39839
GO-2024-3024
BIT-mattermost-2024-39839
GHSA-vg6q-84p8-qvqh
Aug 06, 2024
Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29977
GO-2024-3030
GHSA-jq3g-xqpx-37x3
Aug 06, 2024
Mattermost failed to properly validate synced reactions in github.com/mattermost/mattermost-server Mattermost failed to properly validate synced reactions in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41926
GO-2024-3022
BIT-mattermost-2024-41926
GHSA-9fpw-c9x7-cv3j
Aug 06, 2024
Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-36492
GO-2024-3025
GHSA-56mc-f9w7-2wxq
Aug 06, 2024
Mattermost failed to disallow the modification of local users when syncing users in shared channels in github.com/mattermost/mattermost-server Mattermost failed to disallow the modification of local users when syncing users in shared channels in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41162
GO-2024-3031
BIT-mattermost-2024-41162
GHSA-jr9x-3x7m-4j75
Aug 06, 2024
Mattermost allows a remote actor to make an arbitrary local channel read-only in github.com/mattermost/mattermost-server Mattermost allows a remote actor to make an arbitrary local channel read-only in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39274
GO-2024-3028
GHSA-cmc8-222c-vqp9
Aug 06, 2024
Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel in github.com/mattermost/mattermost-server Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39837
GO-2024-3032
BIT-mattermost-2024-39837
GHSA-vvpg-55p7-5h8w
Aug 06, 2024
Mattermost did not properly restrict channel creation in github.com/mattermost/mattermost-server Mattermost did not properly restrict channel creation in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41144
GO-2024-3023
BIT-mattermost-2024-41144
GHSA-vg67-chm7-8m3j
Aug 06, 2024
Mattermost allows remote actor to create/update/delete posts in arbitrary channels in github.com/mattermost/mattermost-server Mattermost allows remote actor to create/update/delete posts in arbitrary channels in github.com/mattermost/mattermost-server Fixed in
9.5.7+incompatible
9.7.6+incompatible
9.8.2+incompatible
9.9.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.5.5-rc1+incompatible
pre
|
|
v9.4.3+incompatible
minor
54 CVEs
CVE-2026-27769
GO-2026-5522
GHSA-mxxh-fmjq-j6x4
Jun 25, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20250721062209-4952acea88ce before v8.0.0-20260316060126-bc1a2b34b1f9. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-4055
GO-2026-5173
GHSA-6cfr-wp44-6qmv
Jun 25, 2026
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-14350
GO-2026-4521
GHSA-57cc-2pf4-mhmx
Feb 23, 2026
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-13821
GO-2026-4524
GHSA-pp9j-pf5c-659x
Feb 23, 2026
Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-14573
GO-2026-4523
GHSA-cgjg-p2m2-qm4p
Feb 23, 2026
Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-0999
GO-2026-4520
GHSA-3c9r-7f29-qp32
Feb 23, 2026
Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2017-18909
GO-2026-4478
GHSA-r6j5-fqx9-7qv9
Feb 17, 2026
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2017-18912
GO-2026-4487
GHSA-m2ch-x2q7-2284
Feb 17, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server Mattermost Server allows an attacker to specify a full pathname of a log file in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.7.4-0.20170404171331-0b5c0794fdcb. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-62690
GO-2025-4248
GHSA-q66g-q98c-q454
Jan 14, 2026
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18901
GO-2026-4304
GHSA-c253-8hr4-r8v9
Jan 13, 2026
CVE-2017-18901 in github.com/mattermost/mattermost-server CVE-2017-18901 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-14273
GO-2026-4275
GHSA-qvmc-92vg-6r35
Jan 12, 2026
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13324
GO-2025-4256
GHSA-x3r8-2hmh-89f5
Dec 30, 2025
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Fixed in
11.0.4+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12421
GO-2025-4170
GHSA-mp6x-97xj-9x62
Dec 15, 2025
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12559
GO-2025-4169
GHSA-4g87-9x45-cx2h
Dec 15, 2025
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12419
GO-2025-4168
GHSA-3x39-62h4-f8j6
Dec 15, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2017-18870
GO-2025-4183
GHSA-9j9j-mm2r-9rfm
Dec 08, 2025
CVE-2017-18870 in github.com/mattermost/mattermost-server CVE-2017-18870 in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-13870
GO-2025-4178
GHSA-58w6-w55x-6wq8
Dec 08, 2025
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-12756
GO-2025-4172
GHSA-p6gj-jc38-x2m7
Dec 02, 2025
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-21258
GO-2025-4146
GHSA-5mh6-p63g-3mv5
Nov 25, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-41436
GO-2025-4131
GHSA-x3hx-ch7p-8xgg
Nov 18, 2025
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Fixed in
11.0.0-alpha.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-11776
GO-2025-4126
GHSA-j6gg-r5jc-47cm
Nov 17, 2025
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-55070
GO-2025-4128
GHSA-xpg8-8xpv-948p
Nov 17, 2025
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Fixed in
11.1.0+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2016-11075
GO-2025-4061
GHSA-q3g9-hgrx-hwhx
Oct 30, 2025
Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server Mattermost Server exposes sensitive information about team URLs via an API in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v2.0.1-0.20160310160916-26ad6d2c7696. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2016-11066
GO-2025-4047
GHSA-r93j-3mmp-px57
Oct 30, 2025
Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server Mattermost Server: initial_load API exposes unnecessary information in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.1.1. References Updated Nov 05, 2025 · Source: OSV.dev
CVE-2025-41443
GO-2025-4031
GHSA-7cr3-38jm-6p45
Oct 30, 2025
Guest user can discover active public channels in github.com/mattermost/mattermost-server Guest user can discover active public channels in github.com/mattermost/mattermost-server Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3913
GO-2025-3724
GHSA-4mmr-2w8p-whcr
Jun 03, 2025
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3611
GO-2025-3728
GHSA-86jg-35xj-3vv5
Jun 03, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-2571
GO-2025-3729
GHSA-8cgx-9ccj-3gwr
Jun 03, 2025
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-3230
GO-2025-3731
GHSA-mc2f-jgj6-6cp3
Jun 03, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.6.3+incompatible
10.7.1+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1792
GO-2025-3730
GHSA-hc6v-386m-93pq
Jun 03, 2025
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Fixed in
9.11.13+incompatible
10.5.4+incompatible
10.7.1+incompatible
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2025-22445
GO-2025-3380
GHSA-7rgp-4j56-fm79
Jan 09, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
10.3.0+incompatible
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-50052
GO-2024-3235
GHSA-g376-m3h3-mj4r
Nov 04, 2024
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47401
GO-2024-3234
GHSA-762v-rq7q-ff97
Nov 04, 2024
Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-46872
GO-2024-3233
BIT-mattermost-2024-46872
GHSA-762g-9p7f-mrww
Nov 04, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10241
GO-2024-3232
GHSA-6mvp-gh77-7vwh
Oct 30, 2024
Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10214
GO-2024-3227
GHSA-hm57-h27x-599c
Oct 30, 2024
Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-47003
GO-2024-3164
BIT-mattermost-2024-47003
GHSA-59hf-mpf8-pqjh
Oct 10, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1332
GO-2022-0616
BIT-mattermost-2022-1332
GHSA-qggc-pj29-j27m
Aug 21, 2024
Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1337
GO-2022-0595
BIT-mattermost-2022-1337
GHSA-f37q-q7p2-ccfc
Aug 21, 2024
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1384
GO-2022-0576
BIT-mattermost-2022-1384
GHSA-32rp-q37p-jg6w
Aug 21, 2024
Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37860
GO-2022-0604
GHSA-hv5f-73mr-7vvj
Aug 21, 2024
Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1385
GO-2022-0599
BIT-mattermost-2022-1385
GHSA-fxwj-v664-wv5g
Aug 21, 2024
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2401
GO-2022-0540
BIT-mattermost-2022-2401
GHSA-7ggc-5r84-xf54
Aug 21, 2024
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-14457
GO-2023-1939
BIT-mattermost-2020-14457
GHSA-j2h2-cvwh-cr64
Aug 20, 2024
Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-7113
GO-2024-2446
BIT-mattermost-2023-7113
GHSA-h3gq-j7p9-x3p4
Jun 28, 2024
Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-47858
GO-2024-2450
BIT-mattermost-2023-47858
GHSA-w88v-pjr8-cmv2
Jun 28, 2024
Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-50333
GO-2024-2444
BIT-mattermost-2023-50333
GHSA-9w97-9rqx-8v4j
Jun 28, 2024
Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-28949
GO-2024-2695
BIT-mattermost-2024-28949
GHSA-mcw6-3256-64gg
Jun 05, 2024
Mattermost Server doesn't limit the number of user preferences in github.com/mattermost/mattermost-server Mattermost Server doesn't limit the number of user preferences in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 from v8.1.0 before v8.1.11. Fixed in
9.3.3+incompatible
9.4.4+incompatible
9.5.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-4183
GO-2024-2798
GHSA-wj37-mpq9-xrcm
Jun 05, 2024
Mattermost fails to limit the number of active sessions in github.com/mattermost/mattermost-server Mattermost fails to limit the number of active sessions in github.com/mattermost/mattermost-server Fixed in
8.1.12+incompatible
9.4.5+incompatible
9.5.3+incompatible
9.6.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32046
GO-2024-2797
GHSA-vx97-8q8q-qgq5
Jun 05, 2024
Mattermost's detailed error messages reveal the full file path in github.com/mattermost/mattermost-server Mattermost's detailed error messages reveal the full file path in github.com/mattermost/mattermost-server Fixed in
8.1.12+incompatible
9.4.5+incompatible
9.5.3+incompatible
9.6.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29221
GO-2024-2706
BIT-mattermost-2024-29221
GHSA-w67v-ph4x-f48q
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 from v8.1.0 before v8.1.11. Fixed in
9.3.3+incompatible
9.4.4+incompatible
9.5.2+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-4182
GO-2024-2795
GHSA-8f99-g2pj-x8w3
Jun 05, 2024
Mattermost crashes web clients via a malformed custom status in github.com/mattermost/mattermost-server Mattermost crashes web clients via a malformed custom status in github.com/mattermost/mattermost-server Fixed in
8.1.12+incompatible
9.4.5+incompatible
9.5.3+incompatible
9.6.1+incompatible
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2447
GO-2024-2696
BIT-mattermost-2024-2447
GHSA-wp43-vprh-c3w5
Jun 05, 2024
Mattermost fails to authenticate the source of certain types of post actions in github.com/mattermost/mattermost-server Mattermost fails to authenticate the source of certain types of post actions in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 from v8.1.0 before v8.1.11. Fixed in
9.3.3+incompatible
9.4.4+incompatible
9.5.2+incompatible
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-21848
GO-2024-2707
BIT-mattermost-2024-21848
GHSA-xp9j-8p68-9q93
Jun 05, 2024
Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. References Updated Feb 04, 2026 · Source: OSV.dev |
v9.4.3+incompatible
minor
|