Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2024-23319 CSRF issue allows disconnecting a user's Jira connection through a simple post message (Jira Plugin) CWE-352 3.5 Low 2024-02-09
CVE-2023-47858 Details of archived public channels are leaked to members of another team CWE-284 4.3 Medium 2024-01-02
CVE-2023-50333 Lack of restriction to manage group names for freshly demoted guests CWE-284 3.7 Low 2024-01-02
CVE-2023-48732 Keywords that trigger mentions are leaked to other users CWE-200 4.3 Medium 2024-01-02
CVE-2023-7114 Mattermost 安全漏洞 CWE-74 7.1 High 2023-12-29
CVE-2023-7113 Mattermost 安全漏洞 CWE-79 3.7 Low 2023-12-29
CVE-2023-6727 Leak Inaccessible Playbook Information via Channel Action IDOR CWE-200 3.1 Low 2023-12-12
CVE-2023-45316 Reflected client side path traversal leading to CSRF in Playbooks CWE-352 7.3 High 2023-12-12
CVE-2023-6547 Playbooks access/modification by removed team member CWE-284 3.7 Low 2023-12-12
CVE-2023-49607 Playbook plugin crash via missing interface type assertion CWE-754 4.3 Medium 2023-12-12
CVE-2023-49809 Todo plugin gets crashed and disabled by member CWE-400 4.3 Medium 2023-12-12
CVE-2023-46701 Inaccessible Post Information Leak via Run Timeline IDOR CWE-200 6.5 Medium 2023-12-12
CVE-2023-49874 IDOR when updating the tasks of a private playbook run CWE-284 4.3 Medium 2023-12-12
CVE-2023-45847 Playbook Plugin Crash via Run Checklist CWE-400 4.3 Medium 2023-12-12
CVE-2023-6459 Public endpoint /metrics of Calls plugin reveals channel IDs CWE-200 5.3 Medium 2023-12-06
CVE-2023-6458 Client side path traversal due to lack of route parameters validation CWE-74 7.1 High 2023-12-06
CVE-2023-47168 Open redirect in /oauth/<service>/mobile_login?redirect_to= CWE-601 4.3 Medium 2023-11-27
CVE-2023-6202 Insecure Direct Object Reference in /plugins/focalboard/ api/v2/users of Mattermost Boards CWE-284 4.3 Medium 2023-11-27
CVE-2023-43754 Permalink previews displayed for posts in archived channels even if users are disallowed to view archived channels CWE-200 4.3 Medium 2023-11-27
CVE-2023-48369 Log Flooding due to specially crafted requests in different endpoints CWE-400 4.3 Medium 2023-11-27
CVE-2023-35075 HTML injection via channel autocomplete CWE-74 3.1 Low 2023-11-27
CVE-2023-40703 Denial of Service via specially crafted block fields in Mattermost Boards CWE-400 4.3 Medium 2023-11-27
CVE-2023-48268 Denial of Service via Board Import Zip Bomb CWE-400 4.3 Medium 2023-11-27
CVE-2023-45223 Users full name disclosure through Mattermost Boards with Show Full Name Option disabled CWE-200 4.3 Medium 2023-11-27
CVE-2023-47865 Username and Icon override can be used by members when Hardened Mode is enabled CWE-284 4.3 Medium 2023-11-27
CVE-2023-5969 Denial of Service via Link Preview in /api/v4/redirect_location CWE-400 5.3 Medium 2023-11-06
CVE-2023-5968 Password hash in response body after username update CWE-200 4.9 Medium 2023-11-06
CVE-2023-5967 Denial of Service via crashing the Calls Plugin CWE-754 4.3 Medium 2023-11-06
CVE-2023-5522 Mobile app freezes when receiving a post with hundreds of emojis CWE-400 4.3 Medium 2023-10-17
CVE-2023-5339 Mattermost Desktop logs all keystrokes during initial run after fresh installation  CWE-200 4.7 Medium 2023-10-17

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.