VulnSea

mattermost has 64 CVEs on record between 2023 and 2026. Disclosure cadence is accelerating: 23 in the last 90 days against 15 in the 90 before. The busiest recent month was September 2026 with 22. The median CVSS is 5.2 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (5) and CWE-863 (4). Most affected products: Mattermost (23), github.com/mattermost/mattermost/server/v8 (22), github.com/mattermost/mattermost-server (14).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.2
Publish → KEV
—
Last 90 days
23 prev 15

Products

  • Mattermost 23
  • github.com/mattermost/mattermost/server/v8 22
  • github.com/mattermost/mattermost-server 14
  • github.com/mattermost/mattermost-server/v6 2
  • github.com/mattermost/mattermost-plugin-playbooks 1
  • legal_hold 1
64
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

mattermost vulnerabilities

CVEs affecting mattermost, newest first. Open any entry for full detail, references, and exploit status.

64 CVEsRSS

CVE-2026-6739Medium· 6.7
3mo ago

Mattermost doesn't require system-level permission when patching protected default system roles

Mattermost doesn't require system-level permission when patching protected default system roles

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.46%via OSV
CVE-2026-6689Medium· 4.3
3mo ago

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.25%via OSV
CVE-2026-7184Medium· 6.5
3mo ago

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.44%via OSV
CVE-2026-6961High· 7.6
3mo ago

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

▾ Twilightmattermost · github.com/mattermost/mattermost-serverEPSS 0.45%via OSV
CVE-2026-7387High· 8.8
3mo ago

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

▾ Twilightmattermost · github.com/mattermost/mattermost-serverEPSS 0.42%via OSV
CVE-2026-6046Medium· 5.3
3mo ago

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.30%via OSV
CVE-2026-22880Medium· 6.1
4mo ago

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credenti…

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credenti…

▾ Sunlitmattermost · mattermost_mobileEPSS 0.12%via NVD
CVE-2026-3524High· 8.8
5mo ago

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API …

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API …

▾ Twilightmattermost · legal_holdEPSS 0.42%via NVD
CVE-2025-1792Low· 3.1
1y ago

Mattermost fails to properly enforce access controls for guest users

Mattermost fails to properly enforce access controls for guest users

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.24%via OSV
CVE-2025-3611Low· 3.1
1y ago

Mattermost fails to properly enforce access control restrictions for System Manager roles

Mattermost fails to properly enforce access control restrictions for System Manager roles

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.22%via OSV
CVE-2025-35965Medium· 6.5
1y ago

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.40%via OSV
CVE-2025-41395Medium· 6.5
1y ago

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

▾ Sunlitmattermost · github.com/mattermost/mattermost-plugin-playbooksEPSS 0.49%via OSV
CVE-2025-27936Medium· 5.3
1y ago

Mattermost vulnerable to Observable Timing Discrepancy

Mattermost vulnerable to Observable Timing Discrepancy

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.34%via OSV
CVE-2025-2475Medium· 5.4
1y ago

Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm

Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.23%via OSV
CVE-2025-32093Medium· 4.7
1y ago

Mattermost Fails to Restrict Certain Operations on System Admins

Mattermost Fails to Restrict Certain Operations on System Admins

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.24%via OSV
CVE-2025-25279Critical· 9.9PoC
1y ago

Mattermost allows reading arbitrary files related to importing boards

Mattermost allows reading arbitrary files related to importing boards

▾ Abyssalmattermost · github.com/mattermost/mattermost/server/v8EPSS 24%via OSV
CVE-2025-20086Medium· 6.5
1y ago

Mattermost fails to properly validate post props

Mattermost fails to properly validate post props

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.43%via OSV
CVE-2025-20088Medium· 6.5
1y ago

Mattermost fails to properly validate post props

Mattermost fails to properly validate post props

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.56%via OSV
CVE-2025-22445Low· 3.5
1y ago

Mattermost has Improper Check for Unusual or Exceptional Conditions

Mattermost has Improper Check for Unusual or Exceptional Conditions

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.32%via OSV
CVE-2025-20033Medium· 4.3
1y ago

Mattermost Improper Validation of Specified Type of Input vulnerability

Mattermost Improper Validation of Specified Type of Input vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.62%via OSV
CVE-2024-47401Medium· 4.3
1y ago

Mattermost Server vulnerable to application crash from attacker-generated large response

Mattermost Server vulnerable to application crash from attacker-generated large response

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.46%via OSV
CVE-2024-46872Medium· 4.6
1y ago

Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery

Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.15%via OSV
CVE-2024-10241Medium· 4.3
1y ago

Mattermost Server allows user to get private channel names

Mattermost Server allows user to get private channel names

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.29%via OSV
CVE-2024-47003Medium· 5.4
2y ago

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.58%via OSV
CVE-2024-1949Low· 2.6
2y ago

Mattermost race condition

Mattermost race condition

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.27%via OSV
CVE-2024-1952Low· 3.1
2y ago

Mattermost incorrectly allows access individual posts

Mattermost incorrectly allows access individual posts

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.37%via OSV
CVE-2024-23493Medium· 4.3
2y ago

Mattermost leaks details of AD/LDAP groups of a teams

Mattermost leaks details of AD/LDAP groups of a teams

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.39%via OSV
CVE-2024-24988Medium· 4.3
2y ago

Mattermost denial of service through long emoji value

Mattermost denial of service through long emoji value

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.68%via OSV
CVE-2024-1402Medium· 4.3
2y ago

Mattermost vulnerable to denial of service via large number of emoji reactions

Mattermost vulnerable to denial of service via large number of emoji reactions

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.52%via OSV
CVE-2023-6458High· 7.1
2y ago

Mattermost Injection vulnerability

Mattermost Injection vulnerability

▾ Twilightmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.64%via OSV
mattermost vulnerabilities (CVEs) — page 2 · VulnSea