CVE-2025-27571
- EPSS 0.04%
- Published 16.04.2025 07:45:58
- Last modified 01.10.2025 18:20:18
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived Channels" configuration when fetching channel metadata of a post from archived channels, which allows authenticated users to acce...
CVE-2025-27538
- EPSS 0.03%
- Published 16.04.2025 07:45:01
- Last modified 01.10.2025 18:20:09
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate...
CVE-2025-24839
- EPSS 0.03%
- Published 16.04.2025 07:44:20
- Last modified 02.10.2025 14:50:00
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override pr...
CVE-2025-2475
- EPSS 0.04%
- Published 14.04.2025 14:49:36
- Last modified 02.10.2025 14:53:10
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
CVE-2025-2424
- EPSS 0.03%
- Published 14.04.2025 14:49:35
- Last modified 01.10.2025 18:18:33
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
CVE-2025-32093
- EPSS 0.04%
- Published 14.04.2025 07:15:14
- Last modified 02.10.2025 15:02:34
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to ...
CVE-2025-24866
- EPSS 0.04%
- Published 10.04.2025 15:33:21
- Last modified 01.10.2025 18:06:06
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
CVE-2025-25068
- EPSS 0.09%
- Published 21.03.2025 08:26:32
- Last modified 27.03.2025 14:03:38
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.
CVE-2025-24920
- EPSS 0.06%
- Published 21.03.2025 08:25:44
- Last modified 27.03.2025 14:10:53
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels
CVE-2025-30179
- EPSS 0.05%
- Published 21.03.2025 08:24:57
- Last modified 27.03.2025 14:45:47
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries.