Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 422

All 422 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE IDTitleCVSSSeverityPublished
CVE-2025-41443 Guest user can discover active public channels CWE-862 4.3 Medium2025-10-16
CVE-2025-58084 Mattermost Desktop App crashes when clicking on malformed external URL CWE-1287 3.5 Low2025-10-13
CVE-2025-9081 IDOR in board file download allows any user to download any file by UUID CWE-639 3.1 Low2025-09-19
CVE-2025-9079 Admin RCE via prepackaged plugins by way of misconfigured imports directory CWE-22 8.0 High2025-09-19
CVE-2025-9072 One-Click Mattermost Account Takeover via Poisoned RelayState SAML Parameter CWE-601 7.6 High2025-09-15
CVE-2025-9084 Open redirect in OAuth login CWE-601 3.1 Low2025-09-15
CVE-2025-9078 Weak cache keys lead to post IDOR and link preview poisoning CWE-328 4.3 Medium2025-09-15
CVE-2025-9076 Mattermost Server exposes sensitive user credentials during shared channel membership synchronization CWE-862 6.5 Medium2025-09-15
CVE-2025-8402 Nil pointer dereference in bulk import crashes server CWE-1287 4.9 Medium2025-08-21
CVE-2025-6465 Path traversal in image upload with preview overwrite CWE-22 4.3 Medium2025-08-21
CVE-2025-47870 Team invite ID leaked to team admin with no member invite privileges CWE-306 4.3 Medium2025-08-21
CVE-2025-49222 Mattermost Shared Channel Upload Type Validation Bypass CWE-434 6.8 Medium2025-08-21
CVE-2025-8023 Path Traversal in Template Upload Allows Uploading Files Outside Target Directory CWE-22 6.8 Medium2025-08-21
CVE-2025-53971 Channel and Team Membership APIs inadvertently allow loss of Member privileges. CWE-863 3.8 Low2025-08-21
CVE-2025-47700 AI plugin APIs can be triggered using post actions CWE-918 3.5 Low2025-08-21
CVE-2025-49810 Thread summarization allows persistent access to channel CWE-863 3.5 Low2025-08-21
CVE-2025-36530 Import Path Traversal Enables Unauthorized Unsigned Plugin Installation CWE-22 6.8 Medium2025-08-21
CVE-2025-6227 Invite token is used as part of the secure communication CWE-522 2.2 Low2025-07-18
CVE-2025-6233 Arbitrary file read by system admin via path traversal CWE-22 6.8 Medium2025-07-18
CVE-2025-6226 IDOR in CreatePost API allows for timeboxed message disclosure CWE-306 6.5 Medium2025-07-18
CVE-2025-47871 Mattermost Playbooks exposes private channel metadata to unauthorized users via run metadata API CWE-863 4.3 Medium2025-06-30
CVE-2025-46702 Mattermost Playbooks allows privilege escalation through improper access control in playbook run participant management CWE-863 5.4 Medium2025-06-30
CVE-2025-3227 Unauthorized channel member management through playbook runs CWE-863 4.3 Medium2025-06-20
CVE-2025-3228 Unauthorized Guest user access to Playbook CWE-863 4.3 Medium2025-06-20
CVE-2025-4981 Path Traversal Leading to RCE by Any Authenticated Mattermost User CWE-427 9.9 Critical2025-06-20
CVE-2025-4128 Mattermost Guest User Information Disclosure Vulnerability CWE-863 3.1 Low2025-06-11
CVE-2025-4573 LDAP Injection in Mattermost Enterprise Edition When Using Active Directory CWE-90 4.1 Medium2025-06-11
CVE-2025-3611 Improper Access Control in Mattermost allows System Managers to view team details despite role restrictions CWE-863 3.1 Low2025-05-30
CVE-2025-3230 Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server CWE-303 5.4 Medium2025-05-30
CVE-2025-2571 Google OAuth Authentication Bypass for Converted Bot Accounts CWE-303 4.2 Medium2025-05-30

All 422 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.