Filter
AND

go/github.com/mattermost/mattermost/server/v8Denial of service in mattermost mobile apps and server via emoji reactions

First published (updated )

go/github.com/mattermost/mattermost/server/v8Excessive resource consumption when sending long emoji names in user custom status

EPSS
0.04%
First published (updated )

MattermostTeam associated AD/LDAP Groups Leaked due to missing authorization

EPSS
0.04%
First published (updated )

go/github.com/mattermost/mattermost-server/v6Resource Exhaustion via the Invitation Feature

EPSS
0.04%
First published (updated )

MattermostPublic endpoint /metrics of Calls plugin reveals channel IDs

EPSS
0.05%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

go/github.com/mattermost/mattermost/server/v8Invite ID available to team admins even without the "Add Members" permission

EPSS
0.04%
First published (updated )

go/github.com/mattermost/mattermost/server/v8Users maintain access to active call after being removed from a channel

3.1
First published (updated )

go/github.com/mattermost/mattermost/server/v8Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to li…

First published (updated )

go/github.com/mattermost/mattermost/server/v8Infoleak, Race Condition

2.6
First published (updated )

MattermostReflected XSS in Mattermost Jira plugin

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

go/github.com/mattermost/mattermost/server/v8Infoleak

First published (updated )

go/github.com/mattermost/mattermost/server/v8Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata …

First published (updated )

MattermostMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.…

First published (updated )

MattermostMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.…

8.8
First published (updated )

go/github.com/mattermost/mattermost/server/v8Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

go/github.com/mattermost/mattermost/server/v8DoS via a large number of User Preferences

EPSS
0.04%
First published (updated )

MattermostStack overflow in SAML login in Mattermost

7.5
First published (updated )

MattermostStack overflow in document extractor in Mattermost

First published (updated )

MattermostOOM DoS in Mattermost image proxy

First published (updated )

MattermostRestricted custom admin role can bypass the restrictions and view the server logs and server config.json file contents

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

MattermostInvitation Email is resent as a Reminder after invalidating pending email invites

First published (updated )

MattermostAuthorized users are allowed to install old plugin versions from the Marketplace

8.8
First published (updated )

MattermostA crafted SVG attachment can crash a Mattermost server

First published (updated )

MattermostIncorrect defaults can cause attackers to bypass rate limitations

First published (updated )

MattermostTeam members could access sensitive information of other users via an API call

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

MattermostServer-side Denial of Service while processing a specifically crafted JPEG file

First published (updated )

MattermostServer-side Denial of Service while processing a specifically crafted GIF file

First published (updated )

MattermostDisclosure of team owner email address when regenerating Invite ID

2.7
First published (updated )

MattermostDisclosure of team owner email address when when accessing the teams API

2.7
First published (updated )

MattermostReflected XSS in OAuth flow completion endpoints

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203