Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2023-2788 Deactivated user can retain access using oauth2 api CWE-862 6.2 Medium 2023-06-16
CVE-2023-2787 Collapsed Reply Threads APIs leak message contents from private channels CWE-862 6.5 Medium 2023-06-16
CVE-2023-2786 Channel commands execution doesn't properly verify permissions CWE-862 4.3 Medium 2023-06-16
CVE-2023-2808 Lack of URL normalization allows rendering previews for disallowed domains CWE-20 4.3 Medium 2023-05-29
CVE-2023-2514 DB username/password revealed in application logs CWE-200 6.7 Medium 2023-05-12
CVE-2023-2515 Privilege escalation to system admin via personal access tokens CWE-863 4.7 Medium 2023-05-12
CVE-2023-2000 Unrestricted navigation due to unvalidated mattermost server redirection CWE-601 5.4 Medium 2023-05-02
CVE-2023-2281 Archiving a team broadcasts unsanitized data over WebSockets CWE-200 3.1 Low 2023-04-25
CVE-2023-2193 Oauth authorization codes do not expire when deauthorizing an oauth2 app CWE-862 6.5 Medium 2023-04-20
CVE-2023-1831 User password logged in audit logs CWE-200 7.2 High 2023-04-17
CVE-2023-1777 Information disclosure in linked message previews CWE-200 6.5 Medium 2023-03-31
CVE-2023-1776 Stored XSS via SVG attachment on Boards CWE-79 7.3 High 2023-03-31
CVE-2023-1775 Unsanitized events sent over Websocket to regular users in a High Availability environment CWE-200 4.3 Medium 2023-03-31
CVE-2023-1774 Unauthorized email invite to a private channel CWE-862 4.2 Medium 2023-03-31
CVE-2023-1562 Full name revealed via /plugins/focalboard/api/v2/users CWE-200 3.5 Low 2023-03-22
CVE-2023-1421 Reflected XSS in OAuth flow completion endpoints CWE-79 3.5 Low 2023-03-15
CVE-2023-27266 Disclosure of team owner email address when when accessing the teams API CWE-200 2.7 Low 2023-02-27
CVE-2023-27265 Disclosure of team owner email address when regenerating Invite ID CWE-200 2.7 Low 2023-02-27
CVE-2023-27264 IDOR: Updating a playbook via the Playbooks API CWE-862 7.1 High 2023-02-27
CVE-2023-27263 IDOR: Accessing playbook runs via the Playbooks Runs API CWE-862 4.3 Medium 2023-02-27
CVE-2022-4045 Authenticated user could send multiple requests containing a parameter which could fetch a large amount of data and can crash a Mattermost server CWE-770 3.1 Low 2022-11-23
CVE-2022-4044 Authenticated user could send multiple requests containing a large Auto Responder Message payload and can crash a Mattermost server CWE-770 4.3 Medium 2022-11-23
CVE-2022-3257 Server-side Denial of Service while processing a specifically crafted GIF file CWE-400 3.1 Low 2022-09-23
CVE-2022-3147 Server-side Denial of Service while processing a specifically crafted JPEG file CWE-400 3.1 Low 2022-09-09
CVE-2022-2408 Guest accounts can list all public channels CWE-200 4.3 Medium 2022-07-14
CVE-2022-2406 Malicious imports can lead to Denial of Service CWE-400 4.3 Medium 2022-07-14
CVE-2022-2401 Team members could access sensitive information of other users via an API call CWE-200 6.5 Medium 2022-07-14
CVE-2022-2366 Incorrect defaults can cause attackers to bypass rate limitations CWE-276 5.6 Medium 2022-07-11
CVE-2022-1982 A crafted SVG attachment can crash a Mattermost server CWE-400 4.3 Medium 2022-06-02
CVE-2022-1384 Authorized users are allowed to install old plugin versions from the Marketplace CWE-477 4.7 Medium 2022-04-19

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.