Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2026-3471 Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App CWE-939 6.5 Medium 2026-05-18
CVE-2026-4643 Calling window.close() from server-side content causes crash in the Mattermost Desktop App CWE-754 3.5 Low 2026-05-18
CVE-2026-6333 SSRF via Host Header Spoofing in Custom Slash Commands CWE-918 3.5 Low 2026-05-18
CVE-2026-6345 Prevent password disclosure and force reset during Slack import CWE-522 6.5 Medium 2026-05-18
CVE-2026-6346 Sensitive credentials exposed in plaintext in Mattermost support packets CWE-200 8.7 High 2026-05-18
CVE-2026-28732 Slash command trigger-word update allowed command hijacking CWE-863 4.3 Medium 2026-05-18
CVE-2026-6343 Mattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing unauthorized access to public playbooks CWE-863 4.3 Medium 2026-05-18
CVE-2026-6347 Mattermost Calls plugin exposes TURN server credentials in plaintext in support packets CWE-200 7.6 High 2026-05-18
CVE-2026-5163 Missing authorization check in AI message rewrite endpoint allows access to private thread content CWE-862 6.5 Medium 2026-05-18
CVE-2026-3117 Instance and webhook GitLab plugin commands were able to be run by non-admin users CWE-862 6.5 Medium 2026-05-18
CVE-2026-4286 Playbooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook update CWE-863 3.1 Low 2026-05-18
CVE-2026-6339 Missing request origin validation on burn-on-read reveal endpoint CWE-346 4.3 Medium 2026-05-18
CVE-2026-6340 Memory Exhaustion via Malicious 7zip File Upload CWE-789 4.3 Medium 2026-05-18
CVE-2026-6341 Incomplete group locking implementation CWE-863 4.3 Medium 2026-05-18
CVE-2026-6342 Group prefix matching bypass for subscriptions CWE-863 4.3 Medium 2026-05-18
CVE-2026-3495 Unescaped variables during error page composition CWE-79 3.8 Low 2026-05-18
CVE-2026-4273 Insufficient token rotation validation in remote cluster invite confirmation CWE-863 3.7 Low 2026-05-18
CVE-2026-3637 Mattermost fails to enforce create_post permission when editing posts CWE-862 4.3 Medium 2026-05-18
CVE-2026-2325 Improper Input Validation in MS Teams Meetings API Handler CWE-770 4.3 Medium 2026-05-18
CVE-2026-28759 Insufficient authorization in shared channel membership sync allows remote cluster to remove users from arbitrary channels CWE-863 4.3 Medium 2026-05-18
CVE-2026-6334 OAuth authorization code client binding not enforced during token redemption in Mattermost CWE-305 3.1 Low 2026-05-18
CVE-2026-4053 post edit time limit is not enforced on some post update operations CWE-672 3.1 Low 2026-05-15
CVE-2026-4054 SVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of service CWE-754 4.3 Medium 2026-05-15
CVE-2026-3590 Race Condition in Guest Magic Link Authentication Allows Token Reuse CWE-367 6.5 Medium 2026-04-15
CVE-2026-28741 CSRF Protection Bypass Allows Updating a User's Authentication Method CWE-352 6.8 Medium 2026-04-15
CVE-2026-27769 Connected Workspaces: Malicious remote server can manipulate arbitrary user's status CWE-862 2.7 Low 2026-04-15
CVE-2026-24661 Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook Endpoint CWE-770 3.7 Low 2026-04-09
CVE-2026-21388 Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint CWE-770 3.7 Low 2026-04-09
CVE-2026-3524 Authorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission Check CWE-862 8.3 High 2026-04-06
CVE-2026-3112 Arbitrary File Read via Advanced Logging Support Packet CWE-22 6.8 Medium 2026-03-26

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.