mattermost
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting mattermost.
- CVE-2026-96260Mattermost server missing request body size limit on plugin routes allows denial of service by an authenticated user6.5
- CVE-2026-96259Mattermost server-side request forgery via OAuth endpoints configurable by a System Administrator5.5
- CVE-2026-95666Unbounded post ID array in the bulk reactions endpoint allows denial of service4.3
- CVE-2026-12284Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler3.7
- CVE-2026-75588Mattermost Desktop App plugin popout scheme validation bypass2.6
- CVE-2026-75025Mattermost Desktop local network access from server-rendered content4.7
- CVE-2026-91181Data Retention Teams Endpoint Leaks Private Team Invite ID6.5
- CVE-2026-12985Mattermost DCR redirect URI allowlist bypass via improper URL component validation6.8
- CVE-2026-82920Mattermost ABAC parent policy bypass via policy update endpoint5.5
- CVE-2026-86348MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process4.3
- CVE-2026-86349Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting4.3
- CVE-2026-10556Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.5.3
- CVE-2026-13417Boards plugin denial of service via unvalidated block fields.properties4.3
- CVE-2026-9812Missing property field ownership validation in Playbooks run property update endpoint6.5
- CVE-2026-8821Playbooks run owner channel membership permission bypass7.1