Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.0
CVE-2025-54458
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscrip…
Confluence
1.5.0+
HIGH 7.5
CVE-2025-52931
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to up…
Confluence
1.5.0+
HIGH 7.2
CVE-2025-44004
Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create …
Confluence
1.5.0+
MEDIUM 6.4
CVE-2025-48731
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscripti…
Confluence
1.5.0+
MEDIUM 6.5
CVE-2025-6226
Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts…
Mattermost Server
9.11.17 / 10.5.7+
MEDIUM 5.4
CVE-2025-46702
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member…
Mattermost Server
9.11.16 / 10.5.6+
MEDIUM 5.4
CVE-2025-47871
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membe…
Mattermost Server
9.11.16 / 10.5.6+
CRITICAL 9.9
CVE-2025-4981
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archi…
Mattermost Server
9.11.16 / 10.5.6+
MEDIUM 5.4
CVE-2025-3230
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon …
Mattermost Server
9.11.13 / 10.5.4+
MEDIUM 5.3
CVE-2025-31947
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failu…
Mattermost Server
9.11.12 / 10.4.5+
HIGH 7.5
CVE-2025-35965
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the Upd…
Mattermost Server
9.11.11 / 10.4.3+
HIGH 7.5
CVE-2025-41395
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom po…
Mattermost Server
9.11.11 / 10.4.3+
MEDIUM 6.5
CVE-2025-31363
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allow…
Mattermost Server
9.11.10 / 10.4.3+
MEDIUM 5.9
CVE-2025-27936
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant ti…
Mattermost Server
2.1.0 / 10.5.2+
MEDIUM 5.4
CVE-2025-2475
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which…
Mattermost Server
9.11.10 / 10.4.4+
HIGH 7.5
CVE-2025-30516
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauth…
Mattermost Mobile
2.26.0+
MEDIUM 6.5
CVE-2025-1558
Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android a…
Mattermost Mobile
2.25.1+
MEDIUM 6.5
CVE-2025-30179
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attac…
Mattermost Server
9.11.9 / 10.3.4+
HIGH 8.8
CVE-2025-25068
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows auth…
Mattermost Server
9.11.9 / 10.3.4+
HIGH 8.8
CVE-2025-25274
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authen…
Mattermost Server
9.11.9 / 10.3.4+
HIGH 7.5
CVE-2025-25279EPSS 24%
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boar…
Mattermost Server
9.11.8 / 10.2.3+
MEDIUM 6.5
CVE-2025-20051
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicat…
Mattermost Server
9.11.8 / 10.2.3+
MEDIUM 6.5
CVE-2025-24490
Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards…
Mattermost Server
9.11.8 / 10.2.3+
HIGH 8.8
CVE-2025-1412
Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the conver…
Mattermost Server
9.11.7 / 10.4.2+
MEDIUM 5.3
CVE-2025-0503
Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other m…
Mattermost Server
9.11.7+
HIGH 7.5
CVE-2025-20630
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an…
Mattermost Mobile
2.23.0+
HIGH 7.5
CVE-2025-20621
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing …
Mattermost Server
9.11.6 / 10.0.4+
HIGH 7.5
CVE-2025-20072
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allo…
Mattermost Mobile
2.23.0+
MEDIUM 6.5
CVE-2025-20086
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malici…
Mattermost Server
9.11.6 / 10.0.4+
MEDIUM 6.5
CVE-2025-20088
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malici…
Mattermost Server
9.11.6 / 10.0.4+