Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9693 |
|
Vulnerability in mattermost (CVE-2026-9693)
vulnerability in mattermost (CVE-2026-9693). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75587 |
|
Information Disclosure in mattermost (CVE-2026-75587)
vulnerability in mattermost (CVE-2026-75587). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9859 |
|
Authorization Flaw in mattermost (CVE-2026-9859)
vulnerability in mattermost (CVE-2026-9859). Confidential information can be exposed externally.
|
| CVE-2026-9816 |
|
Authorization Flaw in mattermost (CVE-2026-9816)
vulnerability in mattermost (CVE-2026-9816). Data can be tampered with by attackers. Exploitable via `POST /api/v2/boards/{boardID}/members`.
|
| CVE-2026-10080 |
|
Vulnerability in mattermost (CVE-2026-10080)
vulnerability in mattermost (CVE-2026-10080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16045 |
|
Authorization Flaw in mattermost (CVE-2026-16045)
vulnerability in mattermost (CVE-2026-16045). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15754 |
|
Authorization Flaw in mattermost (CVE-2026-15754)
vulnerability in mattermost (CVE-2026-15754). Data can be tampered with by attackers.
|
| CVE-2026-16044 |
|
Authorization Flaw in mattermost (CVE-2026-16044)
vulnerability in mattermost (CVE-2026-16044). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16047 |
|
Vulnerability in mattermost (CVE-2026-16047)
vulnerability in mattermost (CVE-2026-16047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10527 |
|
Authorization Flaw in mattermost (CVE-2026-10527)
vulnerability in mattermost (CVE-2026-10527). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16046 |
|
Authorization Flaw in mattermost (CVE-2026-16046)
vulnerability in mattermost (CVE-2026-16046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16048 |
|
Authorization Flaw in mattermost (CVE-2026-16048)
vulnerability in mattermost (CVE-2026-16048). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7521 |
|
Path Traversal in mattermost (CVE-2026-7521)
path traversal in mattermost (CVE-2026-7521). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10600 |
|
Vulnerability in mattermost (CVE-2026-10600)
vulnerability in mattermost (CVE-2026-10600). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9602 |
|
Vulnerability in mattermost (CVE-2026-9602)
vulnerability in mattermost (CVE-2026-9602). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8075 |
|
Vulnerability in mattermost (CVE-2026-8075)
vulnerability in mattermost (CVE-2026-8075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9824 |
|
Vulnerability in mattermost (CVE-2026-9824)
vulnerability in mattermost (CVE-2026-9824). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9820 |
|
Vulnerability in mattermost (CVE-2026-9820)
vulnerability in mattermost (CVE-2026-9820). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9597 |
|
Vulnerability in mattermost (CVE-2026-9597)
vulnerability in mattermost (CVE-2026-9597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9571 |
|
Vulnerability in mattermost (CVE-2026-9571)
vulnerability in mattermost (CVE-2026-9571). Confidential information can be exposed externally.
|
| CVE-2026-10106 |
|
Authorization Flaw in mattermost (CVE-2026-10106)
vulnerability in mattermost (CVE-2026-10106). Data can be tampered with by attackers.
|
| CVE-2026-10085 |
|
Vulnerability in mattermost (CVE-2026-10085)
vulnerability in mattermost (CVE-2026-10085). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3472 |
|
Vulnerability in mattermost (CVE-2026-3472)
vulnerability in mattermost (CVE-2026-3472). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4339 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-4339)
SSRF in ssrf (CVE-2026-4339). Confidential information can be exposed externally.
|
| CVE-2026-2299 |
|
Vulnerability in mattermost (CVE-2026-2299)
vulnerability in mattermost (CVE-2026-2299). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8823 |
|
Authorization Flaw in mattermost (CVE-2026-8823)
vulnerability in mattermost (CVE-2026-8823). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8074 |
|
Authorization Flaw in mattermost (CVE-2026-8074)
vulnerability in mattermost (CVE-2026-8074). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v4/users/{id}/active`.
|
| CVE-2026-6673 |
|
Vulnerability in mattermost (CVE-2026-6673)
vulnerability in mattermost (CVE-2026-6673). Data can be tampered with by attackers.
|
| CVE-2026-5139 |
|
Vulnerability in mattermost (CVE-2026-5139)
vulnerability in mattermost (CVE-2026-5139). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8683 |
|
Vulnerability in mattermost (CVE-2026-8683)
vulnerability in mattermost (CVE-2026-8683). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6517 |
|
Vulnerability in mattermost (CVE-2026-6517)
vulnerability in mattermost (CVE-2026-6517). Confidential information can be exposed externally.
|
| CVE-2026-7387 |
|
Authorization Flaw in github.com/mattermost/mattermost-server (CVE-2026-7387)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-7387). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2026-6739 |
|
Authorization Flaw in github.com/mattermost/mattermost-server (CVE-2026-6739)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-6739). Confidential information can be exposed externally. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2026-3433 |
|
Information Disclosure in github.com/mattermost/mattermost-server (CVE-2026-3433)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3433). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2026-6961 |
|
Path Traversal in github.com/mattermost/mattermost-server (CVE-2026-6961)
path traversal in github.com/mattermost/mattermost-server (CVE-2026-6961). Data can be tampered with by attackers. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2026-6046 |
|
Information Disclosure in github.com/mattermost/mattermost-server (CVE-2026-6046)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-6046). Confidential information can be exposed externally. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2026-6689 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-6689)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-6689). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v4/teams`. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2026-6957 |
|
Path Traversal in mattermost (CVE-2026-6957)
path traversal in mattermost (CVE-2026-6957). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4915 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4915)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4915). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.15` or later.
|
| CVE-2026-28735 |
|
Authorization Flaw in github.com/mattermost/mattermost-server (CVE-2026-28735)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-28735). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.15` or later.
|
| CVE-2026-5755 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-5755)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-5755). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.15` or later.
|
| CVE-2026-5308 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-5308)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-5308). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.15` or later.
|
| CVE-2026-4646 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4646)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4646). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.15` or later.
|
| CVE-2026-4635 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4635)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4635). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.15` or later.
|
| CVE-2026-3636 |
|
Information Disclosure in github.com/mattermost/mattermost-server (CVE-2026-3636)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3636). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.15` or later.
|
| CVE-2026-4858 |
|
Path Traversal in github.com/mattermost/mattermost-server (CVE-2026-4858)
path traversal in github.com/mattermost/mattermost-server (CVE-2026-4858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.11.15` or later.
|
| CVE-2026-22880 |
|
Cross-Site Request Forgery (CSRF) in mattermost (CVE-2026-22880)
vulnerability in mattermost (CVE-2026-22880). Confidential information can be exposed externally.
|
| CVE-2026-4055 |
|
Authorization Flaw in github.com/mattermost/mattermost/server/v8 (CVE-2026-4055)
vulnerability in github.com/mattermost/mattermost/server/v8 (CVE-2026-4055). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.0-20260320113102-f2b3d1c6a945` or later.
|
| CVE-2026-6346 |
|
Information Disclosure in github.com/mattermost/mattermost/server/v8 (CVE-2026-6346)
vulnerability in github.com/mattermost/mattermost/server/v8 (CVE-2026-6346). Confidential information can be exposed externally. Mitigation: upgrade to `8.0.0-20260326202606-fac92f4a71f3` or later.
|
| CVE-2026-28732 |
|
Authorization Flaw in github.com/mattermost/mattermost/server/v8 (CVE-2026-28732)
vulnerability in github.com/mattermost/mattermost/server/v8 (CVE-2026-28732). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.0-20260306123948-f5fe8ded6b63` or later.
|