github.com/mattermost/mattermost-server/v5

govv5.39.3

Mattermost is an open source platform for secure collaboration across the entire software development lifecycle..

License Apache-2.0permissive393 versions1198 maintainers0 deps36,306 weekly dl
mattermost/mattermost-server/v5
43
/ 100
Health
safe to use

github.com/mattermost/mattermost-server/[email protected] is safe to use (health: 43/100)

Update to >= 8.0.0-20260127144908-ced9a56e3988 to fix known vulnerabilities

Health breakdown0 – 100
0/25
maintenance
10/20
popularity
5/25
security
15/15
maturity
13/15
community
Vulnerabilities
114
10 medium104 low
Advisories (114)
SeverityIDSummaryFixed in
lowCVE-2025-53971Mattermost Fails to Properly Validate Team Role Modification8.0.0-20250721095846-c602a4a78e1f
mediumBIT-mattermost-2023-1776Mattermost vulnerable to cross-site scripting (XSS)7.1.6
mediumBIT-mattermost-2023-1775Mattermost vulnerable to information disclosure 7.1.6
mediumBIT-mattermost-2023-1774Mattermost fails to properly authentication inviter's permissions to private channel7.1.6
mediumCVE-2025-36530Mattermost Fails to Validate File Paths8.0.0-20250619095651-9dd0b3943e55
mediumCVE-2025-8402Mattermost has Potential Server Crash due to Unvalidated Import Data9.11.18
mediumCVE-2025-11776Mattermost fails to properly restrict access to archived channel search API5.3.2-0.20250815165020-c8d66301415d
lowCVE-2025-11777Mattermost Incorrect Authorization vulnerability5.3.2-0.20250905150616-ba86dfc5876b
mediumCVE-2025-49222Mattermost Fails to Validate Remote Cluster Upload Sessions8.0.0-20250708173752-d6b35c41f0ae5
mediumCVE-2025-47870Mattermost Does Not Sanitize the Team Invite ID8.0.0-20250708065844-b38e2eccda18
lowBIT-mattermost-2024-28053Mattermost Server Resource Exhaustion0.0.0-20240209181221-674f549daf0e
mediumCVE-2023-5968Mattermost password hash disclosure vulnerability5.3.2-0.20230825233148-f787fd63368a
lowBIT-mattermost-2024-39837Mattermost did not properly restrict channel creation9.5.7
mediumCVE-2025-8023Mattermost Fails to Sanitize Path Traversal Sequences8.0.0-20250708065844-b38e2eccda18
unknownBIT-mattermost-2022-1337Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server6.4.2
unknownBIT-mattermost-2022-1385Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server6.5.0
unknownBIT-mattermost-2023-50333Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server
unknownBIT-mattermost-2023-7113Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server
unknownBIT-mattermost-2023-48732Mattermost notified all users in the channel when using WebSockets to respond individually in github.com/mattermost/mattermost-server8.1.7+incompatible
unknownBIT-mattermost-2023-47858Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server
... and 94 more
Threat intelligence
1 likely exploited (EPSS ≥ 0.5)
Threat tier per vulnerability derived from CISA KEV catalog + FIRST.org EPSS scores.

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/mattermost/mattermost-server/v5

Last updated · 2021-12-15T17:40:34Z

github.com/mattermost/mattermost-server/v5 — Health Score 43/100 | DepScope | DepScope