Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2024-11358 Insecure Android File Provider Paths CWE-284 5.7 Medium 2024-12-16
CVE-2024-54682 Zipbomb DoS via Missing Slack Import Validation CWE-409 6.5 Medium 2024-12-16
CVE-2024-54083 DoS via lack of type validation in Calls CWE-1287 6.5 Medium 2024-12-16
CVE-2024-48872 Bypass of "Max failed attempts" restriction via race condition CWE-362 4.8 Medium 2024-12-16
CVE-2024-12247 Improper propagation of permission scheme updates across cluster nodes CWE-863 4.6 Medium 2024-12-05
CVE-2024-11599 Domain Restriction Bypass on Registration CWE-754 8.2 High 2024-11-28
CVE-2024-52032 Private channel names leaking when Elasticsearch is enabled CWE-200 4.3 Medium 2024-11-09
CVE-2024-36250 MFA Code Replay CWE-303 3.1 Low 2024-11-09
CVE-2024-42000 Unauthorized Access to view channels' details CWE-863 2.7 Low 2024-11-09
CVE-2024-46872 Client-Side Path Traversal Leading to CSRF in Playbooks CWE-352 4.6 Medium 2024-10-29
CVE-2024-47401 DoS via Amplified GraphQL Response in Playbooks CWE-770 4.3 Medium 2024-10-29
CVE-2024-50052 Arbitrary post deletion via Playbooks /ignore-thread endpoint CWE-862 4.3 Medium 2024-10-29
CVE-2024-10241 Private channel names leaked with Ctrl+K when ElasticSearch is enabled CWE-284 4.3 Medium 2024-10-29
CVE-2024-10214 Incorrect Session Creation with Desktop SSO CWE-303 3.5 Low 2024-10-28
CVE-2024-9155 Insufficient Authorization On Unlinked Channel Files CWE-863 4.3 Medium 2024-09-26
CVE-2024-47003 DoS via non-string message using permalink embed CWE-400 3.1 Low 2024-09-26
CVE-2024-42406 Unauthorized access on archived channels CWE-284 5.4 Medium 2024-09-26
CVE-2024-45843 Weak SSRF Filtering CWE-918 3.1 Low 2024-09-26
CVE-2024-47145 Unauthorized access on archived channels via file links CWE-284 3.1 Low 2024-09-26
CVE-2024-45835 Insufficient Electron Fuses Configuration CWE-693 2.5 Low 2024-09-16
CVE-2024-39772 Silent Desktop Screenshot Capture CWE-284 3.7 Low 2024-09-16
CVE-2024-45833 Mobile password gets saved in dictionary under conditions CWE-693 4.5 Medium 2024-09-16
CVE-2024-39613 RCE in desktop app in Windows by local attacker CWE-427 5.3 Medium 2024-09-16
CVE-2024-43105 Excessive Resource Consumption via `/export` CWE-400 4.3 Medium 2024-08-23
CVE-2024-43780 Unauthorized channel file upload CWE-284 4.3 Medium 2024-08-22
CVE-2024-40884 Unauthorized disabling of invite URL CWE-284 2.7 Low 2024-08-22
CVE-2024-42497 Insufficient permissions checks on teams CWE-284 6.0 Medium 2024-08-22
CVE-2024-8071 System Role with edit access to permissions can elevate themselves to system admin CWE-284 4.7 Medium 2024-08-22
CVE-2024-42411 User creation date manipulation in POST /api/v4/users CWE-754 5.3 Medium 2024-08-22
CVE-2024-40886 One-click Client-Side Path Traversal Leading to CSRF in User Management admin page CWE-352 4.6 Medium 2024-08-22

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.