VulnSea

github.com/mattermost/mattermost/server/v8 vulnerabilities

CVEs whose affected-version data names the github.com/mattermost/mattermost/server/v8 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

33 CVEsRSS

CVE-2026-3433Medium· 4.3
3mo ago

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.18%via OSV
CVE-2026-6739Medium· 6.7
3mo ago

Mattermost doesn't require system-level permission when patching protected default system roles

Mattermost doesn't require system-level permission when patching protected default system roles

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.26%via OSV
CVE-2026-6689Medium· 4.3
3mo ago

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.15%via OSV
CVE-2026-7184Medium· 6.5
3mo ago

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.26%via OSV
CVE-2026-6961High· 7.6
3mo ago

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Twilightmattermost · github.com/mattermost/mattermost-serverEPSS 0.30%via OSV
CVE-2026-7387High· 8.8
3mo ago

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

Twilightmattermost · github.com/mattermost/mattermost-serverEPSS 0.31%via OSV
CVE-2026-6046Medium· 5.3
3mo ago

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.19%via OSV
CVE-2025-1792Low· 3.1
1y ago

Mattermost fails to properly enforce access controls for guest users

Mattermost fails to properly enforce access controls for guest users

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.24%via OSV
CVE-2025-3611Low· 3.1
1y ago

Mattermost fails to properly enforce access control restrictions for System Manager roles

Mattermost fails to properly enforce access control restrictions for System Manager roles

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.22%via OSV
CVE-2025-35965Medium· 6.5
1y ago

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.40%via OSV
CVE-2025-41395Medium· 6.5
1y ago

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

Sunlitmattermost · github.com/mattermost/mattermost-plugin-playbooksEPSS 0.49%via OSV
CVE-2025-27936Medium· 5.3
1y ago

Mattermost vulnerable to Observable Timing Discrepancy

Mattermost vulnerable to Observable Timing Discrepancy

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.34%via OSV
CVE-2025-2475Medium· 5.4
1y ago

Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm

Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.23%via OSV
CVE-2025-32093Medium· 4.7
1y ago

Mattermost Fails to Restrict Certain Operations on System Admins

Mattermost Fails to Restrict Certain Operations on System Admins

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.24%via OSV
CVE-2025-25279Critical· 9.9PoC
1y ago

Mattermost allows reading arbitrary files related to importing boards

Mattermost allows reading arbitrary files related to importing boards

Abyssalmattermost · github.com/mattermost/mattermost/server/v8EPSS 24%via OSV
CVE-2025-20086Medium· 6.5
1y ago

Mattermost fails to properly validate post props

Mattermost fails to properly validate post props

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.43%via OSV
CVE-2025-20088Medium· 6.5
1y ago

Mattermost fails to properly validate post props

Mattermost fails to properly validate post props

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.56%via OSV
CVE-2025-22445Low· 3.5
1y ago

Mattermost has Improper Check for Unusual or Exceptional Conditions

Mattermost has Improper Check for Unusual or Exceptional Conditions

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.32%via OSV
CVE-2025-20033Medium· 4.3
1y ago

Mattermost Improper Validation of Specified Type of Input vulnerability

Mattermost Improper Validation of Specified Type of Input vulnerability

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.62%via OSV
CVE-2024-47401Medium· 4.3
1y ago

Mattermost Server vulnerable to application crash from attacker-generated large response

Mattermost Server vulnerable to application crash from attacker-generated large response

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.46%via OSV
CVE-2024-46872Medium· 4.6
1y ago

Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery

Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.15%via OSV
CVE-2024-10241Medium· 4.3
1y ago

Mattermost Server allows user to get private channel names

Mattermost Server allows user to get private channel names

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.29%via OSV
CVE-2024-47003Medium· 5.4
1y ago

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.58%via OSV
CVE-2024-1949Low· 2.6
2y ago

Mattermost race condition

Mattermost race condition

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.27%via OSV
CVE-2024-1952Low· 3.1
2y ago

Mattermost incorrectly allows access individual posts

Mattermost incorrectly allows access individual posts

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.37%via OSV
CVE-2024-23493Medium· 4.3
2y ago

Mattermost leaks details of AD/LDAP groups of a teams

Mattermost leaks details of AD/LDAP groups of a teams

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.39%via OSV
CVE-2024-24988Medium· 4.3
2y ago

Mattermost denial of service through long emoji value

Mattermost denial of service through long emoji value

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.68%via OSV
CVE-2024-1402Medium· 4.3
2y ago

Mattermost vulnerable to denial of service via large number of emoji reactions

Mattermost vulnerable to denial of service via large number of emoji reactions

Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.52%via OSV
CVE-2023-6458High· 7.1
2y ago

Mattermost Injection vulnerability

Mattermost Injection vulnerability

Twilightmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.64%via OSV
CVE-2023-6459Medium· 5.3
2y ago

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Sunlitmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.53%via OSV
github.com/mattermost/mattermost/server/v8 vulnerabilities (CVEs) · VulnSea