CVE Tools

Mattermost

465 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Mattermost, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.

Mattermost CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Mattermost CVEs per month
MonthCVEs
2024-105
2024-114
2024-125
2025-0112
2025-026
2025-039
2025-0414
2025-059
2025-067
2025-073
2025-089
2025-096
2025-108
2025-1111
2025-1212
2026-012
2026-029
2026-0334
2026-046
2026-0536
2026-0618
2026-0715
2026-0814
2026-0922

Severity

How the 465 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical72%
  • High358%
  • Medium30566%
  • Low11825%

Latest CVEs

The 15 most recently published vulnerabilities affecting Mattermost.

  1. CVE-2026-96260Mattermost server missing request body size limit on plugin routes allows denial of service by an authenticated user6.5
  2. CVE-2026-96259Mattermost server-side request forgery via OAuth endpoints configurable by a System Administrator5.5
  3. CVE-2026-95666Unbounded post ID array in the bulk reactions endpoint allows denial of service4.3
  4. CVE-2026-12284Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler3.7
  5. CVE-2026-75588Mattermost Desktop App plugin popout scheme validation bypass2.6
  6. CVE-2026-75025Mattermost Desktop local network access from server-rendered content4.7
  7. CVE-2026-91181Data Retention Teams Endpoint Leaks Private Team Invite ID6.5
  8. CVE-2026-12985Mattermost DCR redirect URI allowlist bypass via improper URL component validation6.8
  9. CVE-2026-82920Mattermost ABAC parent policy bypass via policy update endpoint5.5
  10. CVE-2026-86348MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process4.3
  11. CVE-2026-86349Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting4.3
  12. CVE-2026-10556Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.5.3
  13. CVE-2026-13417Boards plugin denial of service via unvalidated block fields.properties4.3
  14. CVE-2026-9812Missing property field ownership validation in Playbooks run property update endpoint6.5
  15. CVE-2026-8821Playbooks run owner channel membership permission bypass7.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store