Where
AND
-Infinity
0

Mattermost Mattermost ServerMattermost Server Denial of Service via Animated GIF Emoji Upload

Risk 38
Severity
6.5
First published (updated )

Mattermost Mattermost ServerDenial of service via unbounded document content extraction in Mattermost Server

Risk 22
Severity
4.3
First published (updated )

Mattermost MattermostUnscoped updates to other playbooks' metric configuration

Risk 22
Severity
4.3
First published (updated )

Mattermost Mattermost ServerRemote cluster metadata enumeration via /share-channel autocomplete

Risk 16
Severity
4.3
EPSS
0.16%
First published (updated )

Mattermost MattermostDeactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint

Risk 25
Severity
5.4
EPSS
0.14%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost Mattermost ServerCrafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost

Risk 38
Severity
6.5
First published (updated )

Mattermost MattermostUnauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost

Risk 38
Severity
6.5
First published (updated )

Mattermost MattermostOrdinary group/direct message member can enable group_constrained and remove all channel participants

Risk 34
Severity
5.4
First published (updated )

Mattermost MattermostIncoming webhook user attribution via unvalidated webhook owner

Risk 22
Severity
4.9
EPSS
0.21%
First published (updated )

Mattermost Mattermost ServerAuthenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost Mattermost ServerDeactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost

Risk 27
Severity
6.5
EPSS
0.17%
First published (updated )

Mattermost MattermostSSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server

Risk 36
Severity
6.5
First published (updated )

Mattermost Mattermost ServerIDOR in Jira plugin subscription edit endpoint

Risk 51
Severity
6.4
First published (updated )

Mattermost Mattermost ServerMattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install

Risk 48
Severity
6.4
First published (updated )

Mattermost Mattermost ServerGlobal session revocation does not invalidate active WebSocket connections

Risk 16
Severity
4.3
EPSS
0.33%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost Mattermost ServerGitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration

Risk 34
Severity
5.4
First published (updated )

Mattermost Mattermost ServerPlugin bot username conflict allows user account to be used as bot identity in Mattermost Server

Risk 32
Severity
5.3
First published (updated )

Mattermost Mattermost Server*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings*

Risk 22
Severity
4.3
First published (updated )

Mattermost Mattermost ServerMattermost Remote Cluster PATCH API Leaks Authentication Tokens

Risk 38
Severity
6.5
First published (updated )

Mattermost Mattermost ServerMattermost fails to scope role_updated websocket events to authorized team and channel members

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost Mattermost ServerServer panic via outgoing webhook responses

Risk 38
Severity
6.5
First published (updated )

Mattermost Mattermost ServerGitHub OAuth Scope Validation

Risk 34
Severity
5.4
First published (updated )

Mattermost Mattermost ServerPersistent notification timing attack causing server denial of service

Risk 38
Severity
6.5
First published (updated )

Mattermost Mattermost ServerInsufficient input validation in GitHub plugin API causes denial of service

Risk 22
Severity
4.3
First published (updated )

Mattermost Mattermost ServerSanitize team member data returned by API

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mattermost Mattermost ServerDenial of service via crafted TIFF file upload

Risk 38
Severity
6.5
First published (updated )

Mattermost Mattermost ServerInsufficient permission validation on cross-team playbook run creation

Risk 22
Severity
4.3
First published (updated )

Mattermost Mattermost ServerSSRF via Host Header Spoofing in Custom Slash Commands

Risk 26
Severity
5
First published (updated )

Mattermost Mattermost ServerPrevent password disclosure and force reset during Slack import

Risk 49
Severity
6.5
First published (updated )

Mattermost Mattermost ServerSlash command trigger-word update allowed command hijacking

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203