| CVE-2026-7387 | 8.8 | high | mattermost server | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails t | 85d ago |
| CVE-2026-6346 | 8.7 | high | mattermost server | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuratio | 110d ago |
| CVE-2026-9816 | 8.3 | high | mattermost server | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fi | 19d ago |
| CVE-2026-6957 | 8 | high | legal hold | Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to c | 101d ago |
| CVE-2026-4858 | 8 | high | mattermost server | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integra | 107d ago |
| CVE-2026-6347 | 7.6 | high | mattermost server | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuratio | 110d ago |
| CVE-2026-2476 | 7.6 | high | ms teams | Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker | 173d ago |
| CVE-2026-6961 | 7.6 | high | mattermost server | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails t | 85d ago |
| CVE-2026-24458 | 7.5 | high | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long pass | 173d ago |
| CVE-2026-5740 | 7.5 | high | mattermost server | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly vali | 106d ago |
| CVE-2026-2462 | 6.6 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on | 173d ago |
| CVE-2026-2454 | 5.8 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported arr | 173d ago |
| CVE-2026-2456 | 5.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of r | 173d ago |
| CVE-2026-26304 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, | 173d ago |
| CVE-2026-1629 | 4.3 | medium | mattermost server | Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel | 173d ago |
| CVE-2026-2463 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user | 173d ago |
| CVE-2026-4265 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_f | 173d ago |
| CVE-2026-24692 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissi | 173d ago |
| CVE-2026-25783 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent h | 173d ago |
| CVE-2026-2578 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion whic | 173d ago |
| CVE-2026-21386 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses | 173d ago |
| CVE-2026-2455 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 a | 173d ago |
| CVE-2026-2461 | 4.3 | medium | mattermost server | Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block | 173d ago |
| CVE-2026-2458 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membersh | 173d ago |
| CVE-2026-2457 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post m | 173d ago |
| CVE-2026-25780 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when p | 173d ago |
| CVE-2026-26246 | 4.3 | medium | mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when p | 173d ago |
| CVE-2026-26230 | 3.8 | low | mattermost server | Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles | 173d ago |
| CVE-2026-22545 | 3.1 | low | mattermost server | Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth | 173d ago |