Where
-Infinity
0

Mattermost Mattermost ServerMattermost Server Denial of Service via Animated GIF Emoji Upload

Risk 38
Severity
6.5
First published (updated )

Mattermost Mattermost ServerDenial of service via unbounded document content extraction in Mattermost Server

Risk 22
Severity
4.3
First published (updated )

Mattermost Mattermost Desktop AppPosting a malicious markdown image crashes the Mattermost Desktop App

Risk 38
Severity
6.5
First published (updated )

Mattermost Mattermost Desktop AppMattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods

Risk 27
Severity
6.5
EPSS
0.24%
First published (updated )

Mattermost MattermostUnscoped updates to other playbooks' metric configuration

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost MattermostMattermost schemes teams endpoint exposes private team invite IDs

Risk 20
Severity
3.8
EPSS
0.15%
First published (updated )

Mattermost Mattermost ServerRemote cluster metadata enumeration via /share-channel autocomplete

Risk 16
Severity
4.3
EPSS
0.16%
First published (updated )

Mattermost MattermostDeactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint

Risk 25
Severity
5.4
EPSS
0.14%
First published (updated )

Mattermost Mattermost ServerCrafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost

Risk 38
Severity
6.5
First published (updated )

Mattermost MattermostUnauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost MattermostOrdinary group/direct message member can enable group_constrained and remove all channel participants

Risk 34
Severity
5.4
First published (updated )

Mattermost MattermostIncoming webhook user attribution via unvalidated webhook owner

Risk 22
Severity
4.9
EPSS
0.21%
First published (updated )

Mattermost Mattermost ServerAuthenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels

Risk 22
Severity
4.3
First published (updated )

Mattermost Mattermost ServerDeactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost

Risk 27
Severity
6.5
EPSS
0.17%
First published (updated )

Mattermost MattermostSSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server

Risk 36
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost PluginsMattermost Agents plugin logs unsanitized OpenAI API keys on authentication errors

Risk 27
Severity
6.8
EPSS
0.33%
First published (updated )

Mattermost Mattermost ServerMarkdown image rendering bypass in AI bot tool result posts in Mattermost

Risk 19
Severity
3.5
First published (updated )

Mattermost Mattermost (server/public)Client4 fails to validate path parameters

Risk 34
Severity
5.4
First published (updated )

Mattermost Mattermost Google Drive pluginImproper Access Control in Mattermost Google Drive Plugin File Creation Endpoint

Risk 29
Severity
4.2
First published (updated )

Mattermost Mattermost ServerUser Manager can demote bot accounts to guest without bot-management permission

Risk 20
Severity
3.8
EPSS
0.32%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost Mattermost ServerIDOR in Jira plugin subscription edit endpoint

Risk 51
Severity
6.4
First published (updated )

Mattermost Mattermost ServerMattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install

Risk 48
Severity
6.4
First published (updated )

Mattermost Mattermost ServerImproper Permission Check Allows User Manager to Deactivate Bot Accounts

Risk 26
Severity
3.8
First published (updated )

Mattermost Mattermost ServerGlobal session revocation does not invalidate active WebSocket connections

Risk 16
Severity
4.3
EPSS
0.33%
First published (updated )

Mattermost Mattermost ServerGitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost Mattermost DesktopOverly long URLs crash the Mattermost Desktop App

Risk 27
Severity
6.5
EPSS
0.20%
First published (updated )

Mattermost Mattermost DesktopMattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed

Risk 44
Severity
7.7
First published (updated )

Mattermost Mattermost ServerPath traversal via unsanitized FileInfo.Name in Mattermost federation sync

Risk 47
Severity
7.6
First published (updated )

Mattermost Mattermost ServerMattermost group syncable endpoints allow privilege escalation via scheme_admin

Risk 79
Severity
8.8
First published (updated )

Mattermost Mattermost ServerPlugin bot username conflict allows user account to be used as bot identity in Mattermost Server

Risk 32
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203