Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2024-32045 Playbook run link to private channel grants channel access CWE-284 5.9 Medium 2024-05-26
CVE-2024-34152 Playbook Run Metadata leak to Guest CWE-284 4.3 Medium 2024-05-26
CVE-2024-34029 AD/LDAP Group Members Leak CWE-200 4.3 Medium 2024-05-26
CVE-2024-4198 Mattermost 安全漏洞 CWE-284 2.7 Low 2024-04-26
CVE-2024-4195 Mattermost 安全漏洞 CWE-284 2.7 Low 2024-04-26
CVE-2024-4183 Mattermost 安全漏洞 CWE-400 4.3 Medium 2024-04-26
CVE-2024-4182 Mattermost 安全漏洞 CWE-754 4.3 Medium 2024-04-26
CVE-2024-32046 Detailed error discloses full file path with dev mode off CWE-200 4.3 Medium 2024-04-26
CVE-2024-22091 Excessive resource consumption due to lack to request path size limits CWE-400 3.1 Low 2024-04-26
CVE-2024-3872 Mattermost Mobile Apps 安全漏洞 CWE-400 3.1 Low 2024-04-16
CVE-2024-2447 Mattermost 安全漏洞 CWE-284 6.5 Medium 2024-04-05
CVE-2024-29221 Invite ID available to team admins even without the "Add Members" permission CWE-284 4.7 Medium 2024-04-05
CVE-2024-28949 DoS via a large number of User Preferences CWE-400 4.3 Medium 2024-04-05
CVE-2024-21848 Users maintain access to active call after being removed from a channel CWE-284 3.1 Low 2024-04-05
CVE-2024-2445 Reflected XSS in Mattermost Jira plugin CWE-74 6.1 Medium 2024-03-15
CVE-2024-2450 Mattermost 安全漏洞 CWE-287 8.8 High 2024-03-15
CVE-2024-2446 Mattermost 安全漏洞 CWE-400 4.3 Medium 2024-03-15
CVE-2024-28053 Resource Exhaustion via the Invitation Feature CWE-400 3.1 Low 2024-03-15
CVE-2024-1953 Mattermost 安全漏洞 CWE-400 4.3 Medium 2024-02-29
CVE-2024-1952 Mattermost 安全漏洞 CWE-200 3.1 Low 2024-02-29
CVE-2024-1949 Mattermost 安全漏洞 CWE-200 2.6 Low 2024-02-29
CVE-2024-1942 Mattermost 安全漏洞 CWE-284 4.3 Medium 2024-02-29
CVE-2024-1888 Existing server guests invited to the team by members without "invite_guest" permission CWE-284 4.3 Medium 2024-02-29
CVE-2024-24988 Excessive resource consumption when sending long emoji names in user custom status CWE-400 4.3 Medium 2024-02-29
CVE-2024-1887 Public channel post content accessible without membership when compliance export is enabled CWE-284 4.3 Medium 2024-02-29
CVE-2024-23488 Files of archived channels accessible with the “Allow users to view archived channels” option disabled CWE-284 3.1 Low 2024-02-29
CVE-2024-23493 Team associated AD/LDAP Groups Leaked due to missing authorization CWE-200 4.3 Medium 2024-02-29
CVE-2024-1402 Denial of service in mattermost mobile apps and server via emoji reactions CWE-400 4.3 Medium 2024-02-09
CVE-2024-24776 Incorrect Authorization leads to Channel Member Count Leak CWE-284 3.1 Low 2024-02-09
CVE-2024-24774 Missing authorization allows users to access arbitrary security levels on Jira through webhooks (Jira Plugin) CWE-863 3.4 Low 2024-02-09

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.