Mattermost has 64 CVEs on record between 2023 and 2026. Disclosure cadence is accelerating: 23 in the last 90 days against 15 in the 90 before. The busiest recent month was September 2026 with 22. The median CVSS is 5.2 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (5) and CWE-863 (4). Most affected products: Mattermost (23), github.com/mattermost/mattermost/server/v8 (22), github.com/mattermost/mattermost-server (14).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.2
- Publish → KEV
- —
- Last 90 days
- 23 prev 15
Products
- Mattermost 23
- github.com/mattermost/mattermost/server/v8 22
- github.com/mattermost/mattermost-server 14
- github.com/mattermost/mattermost-server/v6 2
- github.com/mattermost/mattermost-plugin-playbooks 1
- legal_hold 1
Worst active — by depth score
CVE-2025-25279Critical· 9.9Mattermost allows reading arbitrary files related to importing boards71CVE-2026-7387High· 8.8Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints48CVE-2026-3524High· 8.8Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API …48CVE-2026-6961High· 7.6Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync42CVE-2026-8821High· 7.1Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrar…39
Mattermost vulnerabilities
CVEs affecting Mattermost, newest first. Open any entry for full detail, references, and exploit status.
64 CVEsRSS
CVE-2023-6459Medium· 5.3Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-6202Medium· 4.3Mattermost Improper Access Control vulnerability
Mattermost Improper Access Control vulnerability
CVE-2023-47168Medium· 4.3Mattermost Open Redirect vulnerability
Mattermost Open Redirect vulnerability
CVE-2023-48369Medium· 5.3Mattermost Uncontrolled Resource Consumption vulnerability
Mattermost Uncontrolled Resource Consumption vulnerability