Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2026-2476 MS Teams plugin sensitive config values not properly masked in support packets CWE-200 7.6 High 2026-03-16
CVE-2026-2456 Denial of Service via Unbounded Memory Allocation in Integration Actions CWE-789 5.3 Medium 2026-03-16
CVE-2026-1628 Mattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites. CWE-829 4.6 Medium 2026-03-02
CVE-2025-14573 Team Admin Bypass of Invite Permissions via allow_open_invite Field CWE-862 3.8 Low 2026-02-16
CVE-2026-1046 Arbitrary application execution via unvalidated server-controlled URLs in Help menu CWE-939 7.6 High 2026-02-16
CVE-2025-14350 Information disclosure via channel mentions in posts CWE-862 4.3 Medium 2026-02-16
CVE-2025-13821 User profile update exposes password hash and MFA secrets CWE-200 5.7 Medium 2026-02-16
CVE-2026-0997 Mattermost Zoom Plugin channel preference API lacks authorization checks CWE-863 4.3 Medium 2026-02-16
CVE-2026-0998 Mattermost Zoom Plugin allows unauthorized meeting creation and post modification via insufficient API access controls CWE-862 4.3 Medium 2026-02-16
CVE-2026-0999 Authentication bypass via userID login when email and username login are disabled CWE-303 5.4 Medium 2026-02-16
CVE-2026-20796 Time-of-check time-of-use vulnerability in common teams API CWE-367 3.1 Low 2026-02-13
CVE-2026-22892 Insufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post Attachments CWE-863 4.3 Medium 2026-02-13
CVE-2025-14435 Application-Level DoS via infinite re-render loop in user profile handling CWE-770 6.8 Medium 2026-01-16
CVE-2025-14822 DoS from quadratic complexity in model.ParseHashtags CWE-407 3.1 Low 2026-01-16
CVE-2025-64641 Mattermost Jira plugin crafted action leaks Jira issue details CWE-863 4.1 Medium 2025-12-24
CVE-2025-13767 Unauthorized Read Access to Private Channel Posts via Mattermost Jira Plugin CWE-863 4.3 Medium 2025-12-24
CVE-2025-14273 Mattermost Jira plugin user spoofing enables Jira request forgery. CWE-303 7.2 High 2025-12-22
CVE-2025-13326 Mattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App Store CWE-693 3.9 Low 2025-12-17
CVE-2025-13324 Lack of Invalidation of Legacy Remote Cluster Invite Tokens After Confirmation CWE-863 3.7 Low 2025-12-17
CVE-2025-13321 Mattermost Desktop App logging sensitive information and fails to clear data on server deletion CWE-532 3.3 Low 2025-12-17
CVE-2025-12689 DoS in Calls plugin via malformed UTF-8 in WebSocket request CWE-1287 6.5 Medium 2025-12-17
CVE-2025-62690 Open redirect in error page when link opened in new tab CWE-601 3.1 Low 2025-12-17
CVE-2025-13352 Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking CWE-1287 3.0 Low 2025-12-17
CVE-2025-62190 CSRF Allows Call Initiation and Message Delivery CWE-352 4.3 Medium 2025-12-17
CVE-2025-13870 Unauthorized access and subscription vulnerability in Boards CWE-306 3.1 Low 2025-12-02
CVE-2025-12756 Insecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment Deletion CWE-863 4.3 Medium 2025-12-01
CVE-2025-12421 Account Takeover via Code Exchange Endpoint CWE-303 9.9 Critical 2025-11-27
CVE-2025-12559 Information Disclosure in Common Teams API CWE-200 4.3 Medium 2025-11-27
CVE-2025-12419 Account takeover on OAuth/OpenID-enabled servers CWE-303 9.9 Critical 2025-11-27
CVE-2025-55074 Channel member objects leak read status CWE-1426 3.0 Low 2025-11-18

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.