CVE-2025-14435
- EPSS 0.04%
- Veröffentlicht 16.01.2026 11:25:35
- Zuletzt bearbeitet 20.01.2026 15:06:30
Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.
CVE-2025-14822
- EPSS 0.05%
- Veröffentlicht 16.01.2026 08:52:43
- Zuletzt bearbeitet 20.01.2026 15:11:19
Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens
CVE-2025-64641
- EPSS 0.03%
- Veröffentlicht 24.12.2025 08:15:46
- Zuletzt bearbeitet 31.12.2025 18:55:29
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jir...
CVE-2025-13767
- EPSS 0.03%
- Veröffentlicht 24.12.2025 08:15:45
- Zuletzt bearbeitet 31.12.2025 18:56:27
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to...
CVE-2025-14273
- EPSS 0.12%
- Veröffentlicht 22.12.2025 11:24:55
- Zuletzt bearbeitet 29.12.2025 18:47:45
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin,...
CVE-2025-13324
- EPSS 0.04%
- Veröffentlicht 17.12.2025 18:14:13
- Zuletzt bearbeitet 29.12.2025 18:46:13
Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an a...
CVE-2025-12689
- EPSS 0.08%
- Veröffentlicht 17.12.2025 18:14:10
- Zuletzt bearbeitet 29.12.2025 18:44:33
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.
CVE-2025-62690
- EPSS 0.03%
- Veröffentlicht 17.12.2025 12:19:17
- Zuletzt bearbeitet 29.12.2025 18:55:05
Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.
- EPSS 0.05%
- Veröffentlicht 17.12.2025 12:11:25
- Zuletzt bearbeitet 29.12.2025 18:50:47
Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary Git...
CVE-2025-62190
- EPSS 0.02%
- Veröffentlicht 17.12.2025 12:07:37
- Zuletzt bearbeitet 29.12.2025 18:51:51
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject message...