GO-2024-2444: Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server
GO-2024-2446: Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server
GO-2024-2448: Mattermost notified all users in the channel when using WebSockets to respond individually in github.com/mattermost/mattermost-server
GO-2024-2450: Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server
GO-2024-2541: Mattermost vulnerable to denial of service via large number of emoji reactions in github.com/mattermost/mattermost-server
GO-2024-2566: Mattermost fails to check the required permissions in github.com/mattermost/mattermost-server
GO-2024-2588: Mattermost race condition in github.com/mattermost/mattermost-server
GO-2024-2589: Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server
GO-2024-2590: Mattermost leaks details of AD/LDAP groups of a teams in github.com/mattermost/mattermost-server
GO-2024-2591: Mattermost post fetching without auditing in compliance export in github.com/mattermost/mattermost-server
GO-2024-2592: Mattermost allows attackers access to posts in channels they are not a member of in github.com/mattermost/mattermost-server
GO-2024-2593: Mattermost fails to check the "invite_guest" permission in github.com/mattermost/mattermost-server
GO-2024-2594: Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server
GO-2024-2595: Mattermost fails to properly restrict the access of files attached to posts in github.com/mattermost/mattermost-server
GO-2024-2635: Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server
GO-2024-2695: Mattermost Server doesn't limit the number of user preferences in github.com/mattermost/mattermost-server
GO-2024-2696: Mattermost fails to authenticate the source of certain types of post actions in github.com/mattermost/mattermost-server
GO-2024-2706: Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server
GO-2024-2707: Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server
GO-2024-3020: Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server
GO-2024-3022: Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server
GO-2024-3023: Mattermost allows remote actor to create/update/delete posts in arbitrary channels in github.com/mattermost/mattermost-server
GO-2024-3024: Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server
GO-2024-3025: Mattermost failed to disallow the modification of local users when syncing users in shared channels in github.com/mattermost/mattermost-server
GO-2024-3028: Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel in github.com/mattermost/mattermost-server
GO-2024-3030: Mattermost failed to properly validate synced reactions in github.com/mattermost/mattermost-server
GO-2024-3031: Mattermost allows a remote actor to make an arbitrary local channel read-only in github.com/mattermost/mattermost-server
GO-2024-3032: Mattermost did not properly restrict channel creation in github.com/mattermost/mattermost-server
GO-2024-3089: Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server
GO-2024-3090: Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server
GO-2024-3091: Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server
GO-2024-3092: Mattermost allows unsolicited invites to expose access to local channels in github.com/mattermost/mattermost-server
GO-2024-3093: Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server
GO-2024-3094: Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server
GO-2024-3096: Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server
GO-2024-3097: Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server
GO-2024-3334: Mattermost Server Resource Exhaustion in github.com/mattermost/mattermost-server
GO-2024-3337: Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server
GO-2024-3338: Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server
GO-2024-3340: Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server
GO-2025-3534: Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server
GO-2025-3549: Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server
GO-2025-3550: Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server
GO-2025-3551: Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server
GO-2025-3552: Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server
GO-2025-3555: Mattermost fail to prompt for explicit approval before adding a team admin to a private channel in github.com/mattermost/mattermost-server
GO-2025-3604: Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint in github.com/mattermost/mattermost-server
GO-2025-3642: Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks
GO-2025-3642: Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks
GO-2025-3642: Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks
GO-2025-3643: Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks
GO-2025-3643: Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks
GO-2025-3643: Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks
GO-2025-3644: Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks
GO-2025-3644: Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks
GO-2025-3644: Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks
GO-2025-3901: Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server
GO-2025-3904: Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server
GO-2025-3910: Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server
GO-2025-3911: Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server
GO-2025-3950: Mattermost Missing Authorization vulnerability in github.com/mattermost/mattermost-server
GO-2025-3960: Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server
GO-2025-4029: Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server
GO-2025-4035: Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server
GO-2025-4133: Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server
GO-2025-4172: Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost
GO-2025-4247: Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost
GO-2025-4259: Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues in github.com/mattermost/mattermost-server
GO-2025-4260: Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin in github.com/mattermost/mattermost-server
GO-2026-4727: Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server
GO-2026-5404: Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks
GO-2026-5484: Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server
GO-2026-5494: Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks
GO-2026-5629: Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server