CVE-2025-2564
- EPSS 0.04%
- Veröffentlicht 16.04.2025 16:12:14
- Zuletzt bearbeitet 29.09.2025 21:13:11
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of ar...
CVE-2025-27936
- EPSS 0.04%
- Veröffentlicht 16.04.2025 09:14:55
- Zuletzt bearbeitet 16.04.2025 13:25:37
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook sec...
CVE-2025-31363
- EPSS 0.03%
- Veröffentlicht 16.04.2025 09:14:15
- Zuletzt bearbeitet 29.09.2025 21:24:36
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via perf...
CVE-2025-27571
- EPSS 0.04%
- Veröffentlicht 16.04.2025 07:45:58
- Zuletzt bearbeitet 01.10.2025 18:20:18
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived Channels" configuration when fetching channel metadata of a post from archived channels, which allows authenticated users to acce...
CVE-2025-27538
- EPSS 0.03%
- Veröffentlicht 16.04.2025 07:45:01
- Zuletzt bearbeitet 01.10.2025 18:20:09
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate...
CVE-2025-24839
- EPSS 0.03%
- Veröffentlicht 16.04.2025 07:44:20
- Zuletzt bearbeitet 02.10.2025 14:50:00
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override pr...
CVE-2025-2475
- EPSS 0.04%
- Veröffentlicht 14.04.2025 14:49:36
- Zuletzt bearbeitet 02.10.2025 14:53:10
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
CVE-2025-2424
- EPSS 0.03%
- Veröffentlicht 14.04.2025 14:49:35
- Zuletzt bearbeitet 01.10.2025 18:18:33
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
CVE-2025-32093
- EPSS 0.04%
- Veröffentlicht 14.04.2025 07:15:14
- Zuletzt bearbeitet 02.10.2025 15:02:34
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to ...
CVE-2025-24866
- EPSS 0.04%
- Veröffentlicht 10.04.2025 15:33:21
- Zuletzt bearbeitet 01.10.2025 18:06:06
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.