CVE-2025-27571
- EPSS 0.04%
- Veröffentlicht 16.04.2025 07:45:58
- Zuletzt bearbeitet 01.10.2025 18:20:18
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived Channels" configuration when fetching channel metadata of a post from archived channels, which allows authenticated users to acce...
CVE-2025-27538
- EPSS 0.03%
- Veröffentlicht 16.04.2025 07:45:01
- Zuletzt bearbeitet 01.10.2025 18:20:09
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate...
CVE-2025-24839
- EPSS 0.03%
- Veröffentlicht 16.04.2025 07:44:20
- Zuletzt bearbeitet 02.10.2025 14:50:00
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override pr...
CVE-2025-2475
- EPSS 0.04%
- Veröffentlicht 14.04.2025 14:49:36
- Zuletzt bearbeitet 02.10.2025 14:53:10
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
CVE-2025-2424
- EPSS 0.03%
- Veröffentlicht 14.04.2025 14:49:35
- Zuletzt bearbeitet 01.10.2025 18:18:33
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
CVE-2025-32093
- EPSS 0.04%
- Veröffentlicht 14.04.2025 07:15:14
- Zuletzt bearbeitet 02.10.2025 15:02:34
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to ...
CVE-2025-30516
- EPSS 0.03%
- Veröffentlicht 14.04.2025 06:56:22
- Zuletzt bearbeitet 24.09.2025 14:57:30
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifica...
CVE-2025-24866
- EPSS 0.04%
- Veröffentlicht 10.04.2025 15:33:21
- Zuletzt bearbeitet 01.10.2025 18:06:06
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
CVE-2025-1558
- EPSS 0.11%
- Veröffentlicht 24.03.2025 15:15:16
- Zuletzt bearbeitet 25.09.2025 19:14:35
Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.
CVE-2025-25068
- EPSS 0.09%
- Veröffentlicht 21.03.2025 08:26:32
- Zuletzt bearbeitet 27.03.2025 14:03:38
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.