Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 418

All 418 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerability data specifically for the Mattermost open-source collaboration platform. It compiles a comprehensive collection of security flaws, including those related to access control, cross-site scripting, and remote code execution, affecting various versions of the software. The database covers vulnerability records from the initial release of Mattermost up to the most recent publicly disclosed incidents, ensuring a complete historical overview of security issues. Visitors can use this resource to track the vendor’s advisory history, observing how promptly and effectively the development team responds to emerging threats. Users can also analyze the evolution of specific weakness classes within the Mattermost codebase to identify recurring patterns or systemic architectural vulnerabilities. Furthermore, this aggregation allows security professionals and administrators to look up a product’s vulnerability history, providing critical context for risk assessment and patch management decisions. By centralizing these disparate data points, the page serves as a vital reference for evaluating the overall security posture of the Mattermost ecosystem. This information is essential for maintaining secure deployments and understanding the long-term remediation efforts undertaken by the maintainers. The data is strictly factual, focusing on technical details and timeline verification rather than promotional content.

Vendor: Mattermost

CVE IDTitleCVSSSeverityPublished
CVE-2025-3446 Members Without Guest Invite Permissions Can Add Guests to Teams CWE-863 4.3 Medium2025-05-15
CVE-2025-31947 Repeated LDAP login failures can lock an LDAP account CWE-645 5.8 Medium2025-05-15
CVE-2025-41423 Unauthorized Playbooks Post Deletion in Mattermost Playbooks Plugin CWE-863 3.1 Low2025-04-24
CVE-2025-35965 DoS in Mattermost Playbooks via Excessive Task Actions CWE-770 6.5 Medium2025-04-24
CVE-2025-41395 Webapp DoS via malicious retrospective post in Playbooks CWE-1287 6.5 Medium2025-04-24
CVE-2025-2564 Unauthorized View Access to Archived Channel Member Info CWE-863 4.3 Medium2025-04-16
CVE-2025-27936 Webhook Secret Exposure via Timing attack in MSteams plugin CWE-208 5.3 Medium2025-04-16
CVE-2025-31363 Data exfiltration via AI plugin Jira tool CWE-1426 3.0 Low2025-04-16
CVE-2025-27571 Channel metadata visible in archived channels despite configuration setting CWE-863 4.3 Medium2025-04-16
CVE-2025-27538 MFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other Users CWE-306 2.2 Low2025-04-16
CVE-2025-24839 Unauthorized AI bot activation via Wrangler plugin CWE-863 3.1 Low2025-04-16
CVE-2025-2424 Leaked Metadata of Deleted Files via Bookmark Creation CWE-863 3.1 Low2025-04-14
CVE-2025-2475 Unauthorized Bot Login Using Credentials CWE-303 5.4 Medium2025-04-14
CVE-2025-32093 Syatem admin profile modification by delegated granular administration role CWE-863 4.7 Medium2025-04-14
CVE-2025-30516 Unauthorized Notification Exposure in Mobile App Under Specific Conditions CWE-613 2.0 Low2025-04-14
CVE-2025-24866 Unauthorized Access to User Activity Logs API by delegated granular administration roles CWE-863 2.7 Low2025-04-10
CVE-2025-1558 Denial of Service Via Malicious GIF CWE-1287 6.5 Medium2025-03-24
CVE-2025-25068 Bypassing MFA Enforcement on Plugin Endpoints CWE-306 7.5 High2025-03-21
CVE-2025-24920 Unauthorized Bookmark Creation and Modification in Archived Channels CWE-863 4.3 Medium2025-03-21
CVE-2025-30179 MFA Enforcement Bypass in Search APIs CWE-863 4.3 Medium2025-03-21
CVE-2025-25274 Unauthorized Command Execution in Archived Channels CWE-863 4.3 Medium2025-03-21
CVE-2025-27933 Unauthorized Private-to-Public Channel Conversion CWE-863 5.4 Medium2025-03-21
CVE-2025-27715 Auto-Enrollment of Team Admins into Private Channels without explicit consent CWE-863 3.3 Low2025-03-21
CVE-2025-1472 Unauthorized View Access to Site Statistics and Team Statistics CWE-863 4.3 Medium2025-03-19
CVE-2025-1398 macOS TCC Bypass via Code Injection CWE-426 3.3 Low2025-03-17
CVE-2025-20051 Arbitrary file read via block duplication in Mattermost Boards CWE-22 9.9 Critical2025-02-24
CVE-2025-24490 SQL Injection in Mattermost Boards via board category ID reordering CWE-89 9.6 Critical2025-02-24
CVE-2025-25279 Arbitrary file read in Mattermost Boards via import & export board archive CWE-22 9.9 Critical2025-02-24
CVE-2025-1412 Session Persistence After User-to-Bot Conversion CWE-384 3.1 Low2025-02-24
CVE-2025-24526 Channel export permitted on archived channel when viewing archived channels is disabled CWE-863 4.3 Medium2025-02-24

All 418 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.