Where
-Infinity
0

mattermostPermalink Preview Information Disclosure After Permission Revocation

Risk 22
Severity
4.3
First published (updated )

MattermostApplication-Level DoS via infinite re-render loop in user profile handling

Risk 38
Severity
6.8
First published (updated )

Mattermost Mattermost ServerImproper Access Control in Mattermost allows System Managers to view team details despite role restrictions

Risk 22
Severity
4.3
First published (updated )

Mattermost Mattermost ServerBypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server

Risk 34
Severity
5.4
First published (updated )

go/github.com/mattermost/mattermost/server/v8Improper Access Control in Mattermost Channel Member API

Risk 17
Severity
3.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/mattermost/mattermost/server/v8Google OAuth Authentication Bypass for Converted Bot Accounts

Risk 29
Severity
4.2
First published (updated )

Mattermost Mattermost ServerTeam Privacy Settings Authorization Bypass in Mattermost Server

Risk 27
Severity
5.3
First published (updated )

go/github.com/mattermost/mattermost/server/v8System Admin Cannot Access Environment settings in System Console While System Manager Can

Risk 16
Severity
2.7
First published (updated )

go/github.com/mattermost/mattermost/server/v8Improper access control to group information

Risk 22
Severity
4.3
First published (updated )

go/github.com/mattermost/mattermost/server/v8Members Without Guest Invite Permissions Can Add Guests to Teams

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/mattermost/mattermost/server/v8Repeated LDAP login failures can lock an LDAP account

Risk 30
Severity
5.8
First published (updated )

go/github.com/mattermost/mattermost/server/v8Unauthorized Playbooks Post Deletion in Mattermost Playbooks Plugin

Risk 16
Severity
4.3
EPSS
0.02%
First published (updated )

go/github.com/mattermost/mattermost/server/v8DoS in Mattermost Playbooks via Excessive Task Actions

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

go/github.com/mattermost/mattermost/server/v8Webapp DoS via malicious retrospective post in Playbooks

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )

go/github.com/mattermost/mattermost/server/v8Unauthorized View Access to Archived Channel Member Info

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/mattermost/mattermost/server/v8Data exfiltration via AI plugin Jira tool

Risk 38
Severity
6.5
First published (updated )

go/github.com/mattermost/mattermost/server/v8Channel metadata visible in archived channels despite configuration setting

Risk 22
Severity
4.3
First published (updated )

go/github.com/mattermost/mattermost/server/v8MFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other Users

Risk 16
Severity
2.7
First published (updated )

go/github.com/mattermost/mattermost/server/v8Unauthorized AI bot activation via Wrangler plugin

Risk 22
Severity
4.3
First published (updated )

go/github.com/mattermost/mattermost/server/v8Unauthorized Bot Login Using Credentials

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/mattermost/mattermost/server/v8Leaked Metadata of Deleted Files via Bookmark Creation

Risk 22
Severity
4.3
First published (updated )

go/github.com/mattermost/mattermost/server/v8Syatem admin profile modification by delegated granular administration role

Risk 22
Severity
4.9
EPSS
0.03%
First published (updated )

go/github.com/mattermost/mattermost/server/v8Unauthorized Access to User Activity Logs API by delegated granular administration roles

Risk 16
Severity
2.7
First published (updated )

go/github.com/mattermost/mattermost/server/v8Unauthorized Bookmark Creation and Modification in Archived Channels

Risk 22
Severity
4.3
First published (updated )

Mattermost MattermostUnauthorized View Access to Site Statistics and Team Statistics

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/mattermost-desktopmacOS TCC Bypass via Code Injection

Risk 87
Severity
10
First published (updated )

Mattermost, Inc. Mattermost 10.6Reached end of life

EOL
Jun 15, 2025
First published (updated )

Mattermost Mattermost ServerSQL Injection in Mattermost Boards via board category ID reordering

Risk 49
Severity
9.6
EPSS
0.04%
First published (updated )

Mattermost MattermostLeaked User IDs and Metadata of Deleted DMs

Risk 27
Severity
5.3
First published (updated )

Mattermost Mattermost MobileMobile crash via object that can't be cast to String in Attachment Field

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203