Mattermost
465 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Mattermost, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Mattermost CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 5 |
| 2024-11 | 4 |
| 2024-12 | 5 |
| 2025-01 | 12 |
| 2025-02 | 6 |
| 2025-03 | 9 |
| 2025-04 | 14 |
| 2025-05 | 9 |
| 2025-06 | 7 |
| 2025-07 | 3 |
| 2025-08 | 9 |
| 2025-09 | 6 |
| 2025-10 | 8 |
| 2025-11 | 11 |
| 2025-12 | 12 |
| 2026-01 | 2 |
| 2026-02 | 9 |
| 2026-03 | 34 |
| 2026-04 | 6 |
| 2026-05 | 36 |
| 2026-06 | 18 |
| 2026-07 | 15 |
| 2026-08 | 14 |
| 2026-09 | 22 |
Severity
How the 465 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical7
- High35
- Medium305
- Low118
Latest CVEs
The 15 most recently published vulnerabilities affecting Mattermost.
- CVE-2026-96260Mattermost server missing request body size limit on plugin routes allows denial of service by an authenticated user6.5
- CVE-2026-96259Mattermost server-side request forgery via OAuth endpoints configurable by a System Administrator5.5
- CVE-2026-95666Unbounded post ID array in the bulk reactions endpoint allows denial of service4.3
- CVE-2026-12284Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler3.7
- CVE-2026-75588Mattermost Desktop App plugin popout scheme validation bypass2.6
- CVE-2026-75025Mattermost Desktop local network access from server-rendered content4.7
- CVE-2026-91181Data Retention Teams Endpoint Leaks Private Team Invite ID6.5
- CVE-2026-12985Mattermost DCR redirect URI allowlist bypass via improper URL component validation6.8
- CVE-2026-82920Mattermost ABAC parent policy bypass via policy update endpoint5.5
- CVE-2026-86348MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process4.3
- CVE-2026-86349Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting4.3
- CVE-2026-10556Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.5.3
- CVE-2026-13417Boards plugin denial of service via unvalidated block fields.properties4.3
- CVE-2026-9812Missing property field ownership validation in Playbooks run property update endpoint6.5
- CVE-2026-8821Playbooks run owner channel membership permission bypass7.1
Product grouping is registry-driven, with AI assist and human review. How it works