Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2025-11794 Password hash and MFA secret returned in user email verification endpoint CWE-200 4.9 Medium 2025-11-14
CVE-2025-55073 MS Teams plugin OAuth allows editing arbitrary posts CWE-306 5.4 Medium 2025-11-14
CVE-2025-55070 Lack of MFA enforcement in WebSocket connections CWE-306 6.5 Medium 2025-11-14
CVE-2025-41436 Unauthorized access to archived channel content via threads interface CWE-863 3.1 Low 2025-11-14
CVE-2025-11776 Guest user can discover archived public channels CWE-863 4.3 Medium 2025-11-14
CVE-2025-59480 Inadequate validation of SSO redirect credentials permits credential theft CWE-352 6.1 Medium 2025-11-13
CVE-2025-11777 Cross-team channel membership access CWE-863 3.1 Low 2025-11-13
CVE-2025-55035 Mattermost Desktop DoS when user has basic authentication server configured CWE-754 6.1 Medium 2025-10-16
CVE-2025-58073 Arbitrary Mattermost Team can be joined by manipulating the OAuth state CWE-862 8.1 High 2025-10-16
CVE-2025-41410 Slack import bypasses email verification for team access controls CWE-862 5.4 Medium 2025-10-16
CVE-2025-10545 Guest user can add unauthorized team users to private channels CWE-863 3.1 Low 2025-10-16
CVE-2025-58075 Arbitrary Mattermost Team can be joined by manipulating the SAML RelayState CWE-862 8.1 High 2025-10-16
CVE-2025-54499 Insecure string comparison enables timing attacks CWE-208 3.1 Low 2025-10-16
CVE-2025-41443 Guest user can discover active public channels CWE-862 4.3 Medium 2025-10-16
CVE-2025-58084 Mattermost Desktop App crashes when clicking on malformed external URL CWE-1287 3.5 Low 2025-10-13
CVE-2025-9081 IDOR in board file download allows any user to download any file by UUID CWE-639 3.1 Low 2025-09-19
CVE-2025-9079 Admin RCE via prepackaged plugins by way of misconfigured imports directory CWE-22 8.0 High 2025-09-19
CVE-2025-9072 One-Click Mattermost Account Takeover via Poisoned RelayState SAML Parameter CWE-601 7.6 High 2025-09-15
CVE-2025-9084 Open redirect in OAuth login CWE-601 3.1 Low 2025-09-15
CVE-2025-9078 Weak cache keys lead to post IDOR and link preview poisoning CWE-328 4.3 Medium 2025-09-15
CVE-2025-9076 Mattermost Server exposes sensitive user credentials during shared channel membership synchronization CWE-862 6.5 Medium 2025-09-15
CVE-2025-8402 Nil pointer dereference in bulk import crashes server CWE-1287 4.9 Medium 2025-08-21
CVE-2025-6465 Path traversal in image upload with preview overwrite CWE-22 4.3 Medium 2025-08-21
CVE-2025-47870 Team invite ID leaked to team admin with no member invite privileges CWE-306 4.3 Medium 2025-08-21
CVE-2025-49222 Mattermost Shared Channel Upload Type Validation Bypass CWE-434 6.8 Medium 2025-08-21
CVE-2025-8023 Path Traversal in Template Upload Allows Uploading Files Outside Target Directory CWE-22 6.8 Medium 2025-08-21
CVE-2025-53971 Channel and Team Membership APIs inadvertently allow loss of Member privileges. CWE-863 3.8 Low 2025-08-21
CVE-2025-47700 AI plugin APIs can be triggered using post actions CWE-918 3.5 Low 2025-08-21
CVE-2025-49810 Thread summarization allows persistent access to channel CWE-863 3.5 Low 2025-08-21
CVE-2025-36530 Import Path Traversal Enables Unauthorized Unsigned Plugin Installation CWE-22 6.8 Medium 2025-08-21

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.