CVE-2025-3913
- EPSS 0.08%
- Veröffentlicht 29.05.2025 15:10:36
- Zuletzt bearbeitet 03.10.2025 14:02:57
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate permissions when changing team privacy settings, allowing team administrators without the 'invite user' permission to access and mod...
CVE-2025-2570
- EPSS 0.22%
- Veröffentlicht 15.05.2025 15:27:50
- Zuletzt bearbeitet 06.10.2025 15:22:43
Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true ...
CVE-2025-2527
- EPSS 0.17%
- Veröffentlicht 15.05.2025 15:27:49
- Zuletzt bearbeitet 22.08.2025 20:21:35
Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.
CVE-2025-3446
- EPSS 0.19%
- Veröffentlicht 15.05.2025 10:43:46
- Zuletzt bearbeitet 29.09.2025 21:05:33
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct permissions which allows authenticated users who only have permission to invite non-guest users to a team to add guest users to that...
CVE-2025-31947
- EPSS 0.36%
- Veröffentlicht 15.05.2025 10:41:42
- Zuletzt bearbeitet 06.10.2025 15:30:17
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Ma...
CVE-2025-41423
- EPSS 0.04%
- Veröffentlicht 24.04.2025 06:50:12
- Zuletzt bearbeitet 29.09.2025 21:06:37
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing act...
CVE-2025-35965
- EPSS 0.34%
- Veröffentlicht 24.04.2025 06:49:22
- Zuletzt bearbeitet 29.09.2025 21:10:29
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an exce...
CVE-2025-41395
- EPSS 0.13%
- Veröffentlicht 24.04.2025 06:48:31
- Zuletzt bearbeitet 01.10.2025 19:35:27
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with mal...
CVE-2025-2564
- EPSS 0.18%
- Veröffentlicht 16.04.2025 16:12:14
- Zuletzt bearbeitet 29.09.2025 21:13:11
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of ar...
CVE-2025-27936
- EPSS 0.21%
- Veröffentlicht 16.04.2025 09:14:55
- Zuletzt bearbeitet 14.01.2026 14:29:28
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook sec...