Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 418

All 418 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerability data specifically for the Mattermost open-source collaboration platform. It compiles a comprehensive collection of security flaws, including those related to access control, cross-site scripting, and remote code execution, affecting various versions of the software. The database covers vulnerability records from the initial release of Mattermost up to the most recent publicly disclosed incidents, ensuring a complete historical overview of security issues. Visitors can use this resource to track the vendor’s advisory history, observing how promptly and effectively the development team responds to emerging threats. Users can also analyze the evolution of specific weakness classes within the Mattermost codebase to identify recurring patterns or systemic architectural vulnerabilities. Furthermore, this aggregation allows security professionals and administrators to look up a product’s vulnerability history, providing critical context for risk assessment and patch management decisions. By centralizing these disparate data points, the page serves as a vital reference for evaluating the overall security posture of the Mattermost ecosystem. This information is essential for maintaining secure deployments and understanding the long-term remediation efforts undertaken by the maintainers. The data is strictly factual, focusing on technical details and timeline verification rather than promotional content.

Vendor: Mattermost

CVE IDTitleCVSSSeverityPublished
CVE-2023-6202 Insecure Direct Object Reference in /plugins/focalboard/ api/v2/users of Mattermost Boards CWE-284 4.3 Medium2023-11-27
CVE-2023-43754 Permalink previews displayed for posts in archived channels even if users are disallowed to view archived channels CWE-200 4.3 Medium2023-11-27
CVE-2023-48369 Log Flooding due to specially crafted requests in different endpoints CWE-400 4.3 Medium2023-11-27
CVE-2023-35075 HTML injection via channel autocomplete CWE-74 3.1 Low2023-11-27
CVE-2023-40703 Denial of Service via specially crafted block fields in Mattermost Boards CWE-400 4.3 Medium2023-11-27
CVE-2023-48268 Denial of Service via Board Import Zip Bomb CWE-400 4.3 Medium2023-11-27
CVE-2023-45223 Users full name disclosure through Mattermost Boards with Show Full Name Option disabled CWE-200 4.3 Medium2023-11-27
CVE-2023-47865 Username and Icon override can be used by members when Hardened Mode is enabled CWE-284 4.3 Medium2023-11-27
CVE-2023-5969 Denial of Service via Link Preview in /api/v4/redirect_location CWE-400 5.3 Medium2023-11-06
CVE-2023-5968 Password hash in response body after username update CWE-200 4.9 Medium2023-11-06
CVE-2023-5967 Denial of Service via crashing the Calls Plugin CWE-754 4.3 Medium2023-11-06
CVE-2023-5522 Mobile app freezes when receiving a post with hundreds of emojis CWE-400 4.3 Medium2023-10-17
CVE-2023-5339 Mattermost Desktop logs all keystrokes during initial run after fresh installation  CWE-200 4.7 Medium2023-10-17
CVE-2023-5333 Denial of Service via multiple identical User IDs in /api/v4/users/ids CWE-400 4.3 Medium2023-10-09
CVE-2023-5331 File Information Leak via IDOR in file_id in Draft Posts CWE-862 4.3 Medium2023-10-09
CVE-2023-5330 Denial of Service via Opengraph Data Cache CWE-400 4.3 Medium2023-10-09
CVE-2023-5160 Full name disclosure via team top membership with Show Full Name option disabled CWE-200 4.3 Medium2023-10-02
CVE-2023-5194 A system/user manager can demote / deactivate another manager CWE-863 2.7 Low2023-09-29
CVE-2023-5195 A team member can soft delete other teams that they are not part of CWE-863 6.5 Medium2023-09-29
CVE-2023-5193 System Role with manage posts permission can read posts of Direct Messages CWE-863 4.9 Medium2023-09-29
CVE-2023-5196 DoS via Channel Notification Properties CWE-400 6.5 Medium2023-09-29
CVE-2023-5159 A User Manager role with user edit permissions could manage/update bots CWE-863 3.8 Low2023-09-29
CVE-2023-4478 Parameter tampering in the registration resulting in blocked accounts to be created CWE-74 4.3 Medium2023-08-25
CVE-2023-4108 Audit logging fails to sanitize post metadata CWE-532 4.5 Medium2023-08-11
CVE-2023-4107 Incorrect authorization allows a user manager to update a system admin CWE-863 6.7 Medium2023-08-11
CVE-2023-4106 A guest user can perform various actions on public playbooks CWE-862 6.3 Medium2023-08-11
CVE-2023-4105 Attachment of deleted message in a thread remains accessible and downloadable CWE-862 3.1 Low2023-08-11
CVE-2023-3593 Server crash via a specially crafted markdown input CWE-400 4.3 Medium2023-07-17
CVE-2023-3614 Denial of Service via specially crafted gif image CWE-400 4.3 Medium2023-07-17
CVE-2023-3591 Lack of previous password reset tokens on new token creation CWE-287 4.8 Medium2023-07-17

All 418 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.