Vulnerabilities
CVE-2026-5308
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints
CVE-2026-4635
Mattermost doesn't archive the channel before removing persistent notifications
CVE-2026-4915
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing
CVE-2026-3473
Mattermost doesn't validate file ownership and access control
CVE-2026-4646
Mattermost doesn't validate user-supplied input in API request handlers
CVE-2026-5755
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory
CVE-2026-5740
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation
CVE-2026-3636
Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions
CVE-2026-28735
Mattermost allows authenticated users to gain access to private repositories
CVE-2026-4635
Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server
CVE-2026-28735
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github
CVE-2026-4646
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github
CVE-2026-5308
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github
CVE-2026-4915
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server
CVE-2026-3473
Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server
CVE-2026-5740
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server
CVE-2026-5755
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server
CVE-2026-3636
Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server
CVE-2026-6334
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow
CVE-2026-4053
Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields
CVE-2026-3590
Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement
CVE-2026-3495
Mattermost doesn't escape some variables that could contain malicious content during error page composition
CVE-2026-4054
Mattermost doesn't validate the response body of proxied images
CVE-2026-3637
Mattermost doesn't check the create_post channel permission during post edit operations
CVE-2026-6345
Mattermost doesn't prevent disclosure of created user password
CVE-2026-27769
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
CVE-2026-4273
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
CVE-2026-28732
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
CVE-2026-6339
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
CVE-2026-6333
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
CVE-2026-2325
Mattermost doesn't limit the size of the request body on the start meeting API endpoint
CVE-2026-6345
Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server
CVE-2026-6339
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint in github.com/mattermost/mattermost-server
CVE-2026-28732
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server
CVE-2026-6333
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server
CVE-2026-3637
Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server
CVE-2026-27769
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server
CVE-2026-3114
Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server
CVE-2026-27659
Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server
CVE-2026-6343
Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks
CVE-2026-2325
Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings
CVE-2026-28741
Mattermost doesn't validate CSRF tokens on an authentication endpoint in github.com/mattermost/mattermost-server
CVE-2026-3495
Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server
CVE-2026-4054
Mattermost doesn't validate the response body of proxied images in github.com/mattermost/mattermost-server
CVE-2026-3115
Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server
CVE-2026-4053
Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields in github.com/mattermost/mattermost-server
CVE-2026-4273
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server
CVE-2026-3590
Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server
CVE-2026-6334
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server
CVE-2026-4286
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks
CVE-2026-28759
Mattermost does not verify remote cluster channel access when processing shared channel membership removals
CVE-2026-4858
Mattermost has a Path Traversal issue
CVE-2026-5163
Mattermost doesn't verify channel membership when processing AI-assisted message rewrites
CVE-2026-6347
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin
CVE-2026-27656
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw
CVE-2026-6346
Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation
CVE-2026-6340
Mattermost doesn't validate 7zip archive structure before processing
CVE-2026-4274
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
CVE-2026-27656
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server
CVE-2026-6340
Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server
CVE-2026-4858
Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server
CVE-2026-6346
Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server
CVE-2026-28759
Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server
CVE-2026-5163
Mattermost doesn't verify channel membership when processing AI-assisted message rewrites in github.com/mattermost/mattermost-server
CVE-2026-20719
Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server
CVE-2026-6347
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls
CVE-2026-3113
Mattermost doesn't set permissions on downloaded bulk export
CVE-2026-3113
Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server
CVE-2026-3112
Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server
CVE-2026-3108
Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server
CVE-2026-4055
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
CVE-2026-26246
Mattermost fails to bound memory allocation when processing PSD image files
CVE-2026-26246
Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server
CVE-2026-26233
Mattermost doesn't rate limit login requests, allowing DoS
CVE-2026-26233
Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server
CVE-2025-14573
Mattermost fails to enforce invite permissions when updating team settings
CVE-2025-13821
Mattermost fails to sanitize sensitive data in WebSocket messages
CVE-2025-14350
Mattermost fails to properly validate team membership when processing channel mentions
CVE-2026-0999
Mattermost fails to properly validate login method restrictions
CVE-2026-25783
Mattermost fails to properly validate User-Agent header tokens
CVE-2026-2456
Mattermost fails to limit the size of responses from integration action endpoints
CVE-2026-25783
Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server
CVE-2026-2456
Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server
CVE-2026-22545
Mattermost fails to validate user's authentication method when processing account auth type switch
CVE-2026-25780
Mattermost fails to bound memory allocation when processing DOC files
CVE-2026-2457
Mattermost allows attackers to spoof permalink embeds
CVE-2026-21386
Mattermost fails to use consistent error responses when handling the /mute command
CVE-2026-2463
Mattermost fails to filter invite IDs based on user permissions
CVE-2026-2455
Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation
CVE-2026-4265
Mattermost fails to validate team-specific upload_file permissions
CVE-2026-24458
Mattermost fails to properly handle very long passwords
CVE-2026-2458
Mattermost allows a removed team member to enumerate all public channels within a private team
CVE-2026-2578
Mattermost fails to preserve the redacted state of burn-on-read posts during deletion
CVE-2026-24692
Mattermost fails to properly enforce read permissions in search API endpoints
CVE-2026-22545
Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server
CVE-2026-21386
Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server
CVE-2026-4265
Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server
CVE-2026-2455
Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server
CVE-2026-2578
Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server
CVE-2026-24458
Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server
Ready to move
Start Securing
Free, no credit card | First findings in minutes