CVE-2025-58073
- EPSS 0.39%
- Veröffentlicht 16.10.2025 08:44:26
- Zuletzt bearbeitet 21.10.2025 17:51:42
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless ...
CVE-2025-41410
- EPSS 0.28%
- Veröffentlicht 16.10.2025 08:39:58
- Zuletzt bearbeitet 21.10.2025 18:00:54
Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verified user accounts with arbitrary email domains via malicious Slack import...
CVE-2025-10545
- EPSS 0.3%
- Veröffentlicht 16.10.2025 08:24:25
- Zuletzt bearbeitet 21.10.2025 18:02:51
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/m...
CVE-2025-58075
- EPSS 0.31%
- Veröffentlicht 16.10.2025 08:20:06
- Zuletzt bearbeitet 21.10.2025 17:49:14
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless ...
CVE-2025-54499
- EPSS 0.25%
- Veröffentlicht 16.10.2025 08:17:20
- Zuletzt bearbeitet 21.10.2025 17:58:02
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on...
CVE-2025-41443
- EPSS 0.28%
- Veröffentlicht 16.10.2025 08:15:35
- Zuletzt bearbeitet 29.10.2025 08:15:30
Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_...
CVE-2025-58084
- EPSS 0.28%
- Veröffentlicht 13.10.2025 20:15:33
- Zuletzt bearbeitet 29.10.2025 13:34:07
Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
CVE-2025-11579
- EPSS 0.35%
- Veröffentlicht 10.10.2025 11:15:15
- Zuletzt bearbeitet 08.10.2026 13:10:00
github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
CVE-2025-9081
- EPSS 0.27%
- Veröffentlicht 19.09.2025 19:36:14
- Zuletzt bearbeitet 25.09.2025 20:14:59
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration
CVE-2025-9079
- EPSS 0.64%
- Veröffentlicht 19.09.2025 19:22:00
- Zuletzt bearbeitet 25.09.2025 20:16:04
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows admin users to execute arbitrary code via malicious plugin upload to pre...