LIVE · cybersecurity feed
Live wire
vendor

Mattermost

29 CVEs published in the last four months. Exploited flaws first.

Critical0
High10
Medium17
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-73878.8highmattermost serverMattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails t85d ago
CVE-2026-63468.7highmattermost serverMattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuratio110d ago
CVE-2026-98168.3highmattermost serverMattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fi19d ago
CVE-2026-69578highlegal holdMattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to c101d ago
CVE-2026-48588highmattermost serverMattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integra107d ago
CVE-2026-63477.6highmattermost serverMattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuratio110d ago
CVE-2026-24767.6highms teamsMattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker173d ago
CVE-2026-69617.6highmattermost serverMattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails t85d ago
CVE-2026-244587.5highmattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long pass173d ago
CVE-2026-57407.5highmattermost serverMattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly vali106d ago
CVE-2026-24626.6mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on173d ago
CVE-2026-24545.8mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported arr173d ago
CVE-2026-24565.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of r173d ago
CVE-2026-263044.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, 173d ago
CVE-2026-16294.3mediummattermost serverMattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel 173d ago
CVE-2026-24634.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user173d ago
CVE-2026-42654.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_f173d ago
CVE-2026-246924.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissi173d ago
CVE-2026-257834.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent h173d ago
CVE-2026-25784.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion whic173d ago
CVE-2026-213864.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses173d ago
CVE-2026-24554.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 a173d ago
CVE-2026-24614.3mediummattermost serverMattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block173d ago
CVE-2026-24584.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membersh173d ago
CVE-2026-24574.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post m173d ago
CVE-2026-257804.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when p173d ago
CVE-2026-262464.3mediummattermost serverMattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when p173d ago
CVE-2026-262303.8lowmattermost serverMattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles173d ago
CVE-2026-225453.1lowmattermost serverMattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth173d ago

Filter the full tracker by Mattermost