Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2023-5333 Denial of Service via multiple identical User IDs in /api/v4/users/ids CWE-400 4.3 Medium 2023-10-09
CVE-2023-5331 File Information Leak via IDOR in file_id in Draft Posts CWE-862 4.3 Medium 2023-10-09
CVE-2023-5330 Denial of Service via Opengraph Data Cache CWE-400 4.3 Medium 2023-10-09
CVE-2023-5160 Full name disclosure via team top membership with Show Full Name option disabled CWE-200 4.3 Medium 2023-10-02
CVE-2023-5194 A system/user manager can demote / deactivate another manager CWE-863 2.7 Low 2023-09-29
CVE-2023-5195 A team member can soft delete other teams that they are not part of CWE-863 6.5 Medium 2023-09-29
CVE-2023-5193 System Role with manage posts permission can read posts of Direct Messages CWE-863 4.9 Medium 2023-09-29
CVE-2023-5196 DoS via Channel Notification Properties CWE-400 6.5 Medium 2023-09-29
CVE-2023-5159 A User Manager role with user edit permissions could manage/update bots CWE-863 3.8 Low 2023-09-29
CVE-2023-4478 Parameter tampering in the registration resulting in blocked accounts to be created CWE-74 4.3 Medium 2023-08-25
CVE-2023-4108 Audit logging fails to sanitize post metadata CWE-532 4.5 Medium 2023-08-11
CVE-2023-4107 Incorrect authorization allows a user manager to update a system admin CWE-863 6.7 Medium 2023-08-11
CVE-2023-4106 A guest user can perform various actions on public playbooks CWE-862 6.3 Medium 2023-08-11
CVE-2023-4105 Attachment of deleted message in a thread remains accessible and downloadable CWE-862 3.1 Low 2023-08-11
CVE-2023-3593 Server crash via a specially crafted markdown input CWE-400 4.3 Medium 2023-07-17
CVE-2023-3614 Denial of Service via specially crafted gif image CWE-400 4.3 Medium 2023-07-17
CVE-2023-3591 Lack of previous password reset tokens on new token creation CWE-287 4.8 Medium 2023-07-17
CVE-2023-3590 Deleted attachments in Boards remain accessible CWE-863 3.1 Low 2023-07-17
CVE-2023-3587 Inconsistent state in UI after boards permission change by system admin CWE-862 2.7 Low 2023-07-17
CVE-2023-3586 Disabling publicly-shared boards does not disable existing publicly available board links CWE-863 4.2 Medium 2023-07-17
CVE-2023-3585 channel DoS by sharing a boards link CWE-400 4.3 Medium 2023-07-17
CVE-2023-3584 Member can create team with team override scheme CWE-863 3.1 Low 2023-07-17
CVE-2023-3582 Lack of channel membership check when linking a board to a channel CWE-863 4.3 Medium 2023-07-17
CVE-2023-3581 WebSockets accept connections from HTTPS origin CWE-346 6.2 Medium 2023-07-17
CVE-2023-3577 Limited blind SSRF to localhost/intranet in interactive dialog implementation CWE-918 3.5 Low 2023-07-17
CVE-2023-2785 Specially crafted search query can cause large log entries in postgres CWE-400 4.3 Medium 2023-06-16
CVE-2023-2831 Denial of Service while unescaping a Markdown string CWE-400 4.3 Medium 2023-06-16
CVE-2023-2793 Stack exhaustion in PreparePostForClientWithEmbedsAndImages CWE-400 6.5 Medium 2023-06-16
CVE-2023-2792 Ephemeral messages return private channel contents in permalink previews CWE-200 6.5 Medium 2023-06-16
CVE-2023-2791 Playbooks lets you edit arbitrary posts CWE-862 4.3 Medium 2023-06-16

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.