Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2025-6227 Invite token is used as part of the secure communication CWE-522 2.2 Low 2025-07-18
CVE-2025-6233 Arbitrary file read by system admin via path traversal CWE-22 6.8 Medium 2025-07-18
CVE-2025-6226 IDOR in CreatePost API allows for timeboxed message disclosure CWE-306 6.5 Medium 2025-07-18
CVE-2025-47871 Mattermost Playbooks exposes private channel metadata to unauthorized users via run metadata API CWE-863 4.3 Medium 2025-06-30
CVE-2025-46702 Mattermost Playbooks allows privilege escalation through improper access control in playbook run participant management CWE-863 5.4 Medium 2025-06-30
CVE-2025-3227 Unauthorized channel member management through playbook runs CWE-863 4.3 Medium 2025-06-20
CVE-2025-3228 Unauthorized Guest user access to Playbook CWE-863 4.3 Medium 2025-06-20
CVE-2025-4981 Path Traversal Leading to RCE by Any Authenticated Mattermost User CWE-427 9.9 Critical 2025-06-20
CVE-2025-4128 Mattermost Guest User Information Disclosure Vulnerability CWE-863 3.1 Low 2025-06-11
CVE-2025-4573 LDAP Injection in Mattermost Enterprise Edition When Using Active Directory CWE-90 4.1 Medium 2025-06-11
CVE-2025-3611 Improper Access Control in Mattermost allows System Managers to view team details despite role restrictions CWE-863 3.1 Low 2025-05-30
CVE-2025-3230 Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server CWE-303 5.4 Medium 2025-05-30
CVE-2025-2571 Google OAuth Authentication Bypass for Converted Bot Accounts CWE-303 4.2 Medium 2025-05-30
CVE-2025-1792 Improper Access Control in Mattermost Channel Member API CWE-863 3.1 Low 2025-05-30
CVE-2025-3913 Team Privacy Settings Authorization Bypass in Mattermost Server CWE-863 5.3 Medium 2025-05-29
CVE-2025-2570 System Admin Cannot Access Environment settings in System Console While System Manager Can CWE-863 2.7 Low 2025-05-15
CVE-2025-2527 Improper access control to group information CWE-863 4.3 Medium 2025-05-15
CVE-2025-3446 Members Without Guest Invite Permissions Can Add Guests to Teams CWE-863 4.3 Medium 2025-05-15
CVE-2025-31947 Repeated LDAP login failures can lock an LDAP account CWE-645 5.8 Medium 2025-05-15
CVE-2025-41423 Unauthorized Playbooks Post Deletion in Mattermost Playbooks Plugin CWE-863 3.1 Low 2025-04-24
CVE-2025-35965 DoS in Mattermost Playbooks via Excessive Task Actions CWE-770 6.5 Medium 2025-04-24
CVE-2025-41395 Webapp DoS via malicious retrospective post in Playbooks CWE-1287 6.5 Medium 2025-04-24
CVE-2025-2564 Unauthorized View Access to Archived Channel Member Info CWE-863 4.3 Medium 2025-04-16
CVE-2025-27936 Webhook Secret Exposure via Timing attack in MSteams plugin CWE-208 5.3 Medium 2025-04-16
CVE-2025-31363 Data exfiltration via AI plugin Jira tool CWE-1426 3.0 Low 2025-04-16
CVE-2025-27571 Channel metadata visible in archived channels despite configuration setting CWE-863 4.3 Medium 2025-04-16
CVE-2025-27538 MFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other Users CWE-306 2.2 Low 2025-04-16
CVE-2025-24839 Unauthorized AI bot activation via Wrangler plugin CWE-863 3.1 Low 2025-04-16
CVE-2025-2475 Unauthorized Bot Login Using Credentials CWE-303 5.4 Medium 2025-04-14
CVE-2025-2424 Leaked Metadata of Deleted Files via Bookmark Creation CWE-863 3.1 Low 2025-04-14

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.