Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2022-1385 Invitation Email is resent as a Reminder after invalidating pending email invites CWE-664 3.7 Low 2022-04-19
CVE-2022-1332 Restricted custom admin role can bypass the restrictions and view the server logs and server config.json file contents CWE-200 4.3 Medium 2022-04-13
CVE-2022-1337 OOM DoS in Mattermost image proxy CWE-400 4.3 Medium 2022-04-13
CVE-2022-1002 HTML Injection while inviting Guests CWE-80 2.0 Low 2022-03-18
CVE-2022-1003 Sysadmin can override existing configs & bypass restrictions like EnableUploads CWE-268 3.3 Low 2022-03-18
CVE-2022-0904 Stack overflow in document extractor in Mattermost 4.3 Medium 2022-03-09
CVE-2022-0903 Stack overflow in SAML login in Mattermost 5.3 Medium 2022-03-09
CVE-2022-0708 Team Creator's Email Address is disclosed to Team Members via one of the APIs CWE-200 4.3 Medium 2022-02-21
CVE-2021-37864 Users can view the contents of an archived channel when access is explicitly denied by the system admin CWE-284 2.6 Low 2022-01-18
CVE-2021-37865 Server-side Denial of Service while processing a specifically crafted GIF file CWE-400 4.3 Medium 2022-01-18
CVE-2021-37863 Mattermost 输入验证错误漏洞 CWE-20 3.5 Low 2021-12-17
CVE-2021-37862 Mattermost 代码问题漏洞 CWE-754 3.7 Low 2021-12-17
CVE-2021-37861 Mattermost 日志信息泄露漏洞 CWE-532 5.8 Medium 2021-12-09
CVE-2021-37860 Mattermost 跨站脚本漏洞 CWE-79 3.7 Low 2021-09-22
CVE-2021-37859 Reflected XSS in OAuth Flow CWE-79 7.1 High 2021-08-05

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.