github.com/mattermost/mattermost-server/v6

govv6.7.2

Mattermost is an open source platform for secure collaboration across the entire software development lifecycle..

License Apache-2.0permissive39 versions1198 maintainers0 deps36,306 weekly dl
mattermost/mattermost-server/v6
35
/ 100
Health
update required

github.com/mattermost/mattermost-server/[email protected] has vulnerabilities — update to latest

Update to >= 8.0.0-20260127144908-ced9a56e3988 to fix known vulnerabilities

  • Low health score (35/100)
  • 2 high severity vulnerabilities
Health breakdown0 – 100
0/25
maintenance
10/20
popularity
0/25
security
12/15
maturity
13/15
community
Vulnerabilities
139
2 high31 medium106 low
Advisories (139)
SeverityIDSummaryFixed in
mediumCVE-2023-5196Mattermost Uncontrolled Resource Consumption vulnerability7.8.10
mediumCVE-2023-48369Mattermost Uncontrolled Resource Consumption vulnerability7.8.13
mediumBIT-mattermost-2023-1777Mattermost vulnerable to information disclosure1.4.1-0.20230301145909-10be118d99a5
lowCVE-2025-53971Mattermost Fails to Properly Validate Team Role Modification8.0.0-20250721095846-c602a4a78e1f
mediumCVE-2023-2783Mattermost Server Missing Authorization vulnerability6.0.0-20230511130429-1629a6ca7fed
mediumCVE-2023-47168Mattermost Open Redirect vulnerability7.8.13
mediumBIT-mattermost-2023-6459Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability8.1.5
mediumBIT-mattermost-2023-1776Mattermost vulnerable to cross-site scripting (XSS)7.1.6
mediumCVE-2023-4107Mattermost does not validate requesting user permissions before updating admin details7.10.4
highBIT-mattermost-2023-6458Mattermost Injection vulnerability9.1.2
highBIT-mattermost-2023-2515Mattermost Incorrect Authorization vulnerability7.9.2
mediumCVE-2023-6202Mattermost Improper Access Control vulnerability7.8.13
mediumBIT-mattermost-2023-1775Mattermost vulnerable to information disclosure 7.1.6
mediumBIT-mattermost-2023-1774Mattermost fails to properly authentication inviter's permissions to private channel7.1.6
mediumCVE-2023-5195Mattermost Incorrect Authorization vulnerability7.8.10
mediumCVE-2023-4108Mattermost fails to sanitize post metadata7.10.4
mediumCVE-2023-40703Mattermost Uncontrolled Resource Consumption vulnerability7.8.13
lowCVE-2023-4105Mattermost fails to correctly delete attachments7.8.8
mediumCVE-2025-36530Mattermost Fails to Validate File Paths8.0.0-20250619095651-9dd0b3943e55
mediumCVE-2025-8402Mattermost has Potential Server Crash due to Unvalidated Import Data9.11.18
... and 119 more
Threat intelligence
1 likely exploited (EPSS ≥ 0.5)
Threat tier per vulnerability derived from CISA KEV catalog + FIRST.org EPSS scores.

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/mattermost/mattermost-server/v6

Last updated · 2022-06-14T11:04:53Z

github.com/mattermost/mattermost-server/v6 — Health Score 35/100 | DepScope | DepScope