Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2024-43813 IDOR when marking read a user's channel CWE-284 4.3 Medium 2024-08-22
CVE-2024-39810 Server crash via Elasticsearch certificate file CWE-400 4.9 Medium 2024-08-22
CVE-2024-32939 Email addresses of remote users visible in props regardless of server settings CWE-284 4.3 Medium 2024-08-22
CVE-2024-39836 Munged email address used for password resets and notifications CWE-693 4.8 Medium 2024-08-22
CVE-2024-41926 Malicious remote can claim that a user was synced from another remote CWE-284 2.7 Low 2024-08-01
CVE-2024-41162 Malicious remote can make an arbitrary local channel read-only CWE-284 4.1 Medium 2024-08-01
CVE-2024-41144 Malicious remote can create/update/delete arbitrary posts in arbitrary channels CWE-284 5.5 Medium 2024-08-01
CVE-2024-39839 Remote username set to an arbitrary string by remote user CWE-284 4.3 Medium 2024-08-01
CVE-2024-39837 Malicious remote can create arbitrary channels CWE-284 3.8 Low 2024-08-01
CVE-2024-39832 Permanently local data deletion by malicious remote CWE-754 6.8 Medium 2024-08-01
CVE-2024-39777 Malicious remote can invite itself to an arbitrary local channel CWE-284 8.7 High 2024-08-01
CVE-2024-39274 Malicious remote can add users to arbitrary teams and channels CWE-284 8.7 High 2024-08-01
CVE-2024-36492 Existing local user overwritten by malicious remote CWE-284 7.4 High 2024-08-01
CVE-2024-29977 Malicious remote can create arbitrary reactions on arbitrary posts CWE-284 2.7 Low 2024-08-01
CVE-2024-39767 Spoofed push notifications from malicious server CWE-287 4.2 Medium 2024-07-15
CVE-2024-32945 LaTeX post content manipulation via renderer state leak across contexts CWE-909 2.6 Low 2024-07-15
CVE-2024-6428 Limited DoS due to permitting creating users with user-defined IDs CWE-284 5.3 Medium 2024-07-03
CVE-2024-39353 RemoteClusterFrame payloads are audit logged in full CWE-200 2.7 Low 2024-07-03
CVE-2024-39361 Creating posts with user-defined IDs permitted in CreatePost API CWE-284 3.1 Low 2024-07-03
CVE-2024-39830 Timing attack during remote cluster token comparison when shared channels are enabled CWE-287 8.1 High 2024-07-03
CVE-2024-39807 Channel IDs of archived/restored channels leaked via webhook events CWE-200 3.1 Low 2024-07-03
CVE-2024-36257 Lack of permission check when updating the profile picture of a remote user (shared channels enabled) CWE-284 2.7 Low 2024-07-03
CVE-2024-37182 Lack of permissions prompting when opening external URLs CWE-693 4.7 Medium 2024-06-14
CVE-2024-36287 Bypass of TCC restrictions on macOS CWE-693 3.8 Low 2024-06-14
CVE-2024-29215 Slash commands run in channel without channel membership via playbook task commands CWE-284 4.3 Medium 2024-05-26
CVE-2024-36255 Post actions can run playbook checklist task commands CWE-352 5.7 Medium 2024-05-26
CVE-2024-36241 /playbook add slash command allows viewing arbitrary post contents CWE-284 3.1 Low 2024-05-26
CVE-2024-31859 Member promoted to channel admin via playbooks run linking to channel CWE-284 4.3 Medium 2024-05-26
CVE-2024-5270 SAML to email switch possible when email signin is disabled CWE-284 4.3 Medium 2024-05-26
CVE-2024-5272 Run Details leak to guest via webhook event "custom_playbooks_playbook_run_updated" CWE-284 4.3 Medium 2024-05-26

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.