Mattermost
This hub aggregates every CVE we track for Mattermost, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
465
CVEs tracked
7
Critical
35
High
0
In CISA KEV
Severity distribution
MEDIUM305LOW118HIGH35CRITICAL7
Monthly trend
5
4
5
12
6
9
14
9
7
3
9
6
8
11
12
2
9
34
6
36
18
15
14
22
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Mattermost.
- CVE-2026-96260Mattermost server missing request body size limit on plugin routes allows denial of service by an authenticated user6.5
- CVE-2026-96259Mattermost server-side request forgery via OAuth endpoints configurable by a System Administrator5.5
- CVE-2026-95666Unbounded post ID array in the bulk reactions endpoint allows denial of service4.3
- CVE-2026-12284Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler3.7
- CVE-2026-75588Mattermost Desktop App plugin popout scheme validation bypass2.6
- CVE-2026-75025Mattermost Desktop local network access from server-rendered content4.7
- CVE-2026-91181Data Retention Teams Endpoint Leaks Private Team Invite ID6.5
- CVE-2026-12985Mattermost DCR redirect URI allowlist bypass via improper URL component validation6.8
- CVE-2026-82920Mattermost ABAC parent policy bypass via policy update endpoint5.5
- CVE-2026-86348MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process4.3
- CVE-2026-86349Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting4.3
- CVE-2026-10556Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.5.3
- CVE-2026-13417Boards plugin denial of service via unvalidated block fields.properties4.3
- CVE-2026-9812Missing property field ownership validation in Playbooks run property update endpoint6.5
- CVE-2026-8821Playbooks run owner channel membership permission bypass7.1
Product normalization is registry-driven with AI assist and human review. How it works