5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-14822
Mattermost Web
3.1
LOW
EPSS
0.0%
2025 CWE-407 1 PoC

Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens

CVE-2025-24839
Mattermost General
3.1
LOW
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override property to a post via the Wrangler plugin, provided both the AI and Wrangler plugins are enabled.

CVE-2025-10545
Mattermost Web
3.1
LOW
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint

CVE-2025-1412
Mattermost General
3.1
LOW
EPSS
0.2%
2025 CWE-384 1 PoC

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

CVE-2025-62690
Mattermost General
3.1
LOW
EPSS
0.1%
2025 CWE-601 1 PoC

Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.

CVE-2025-54499
Mattermost Web Database Cloud
3.1
LOW
EPSS
0.0%
2025 CWE-208 1 PoC

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets

CVE-2025-9081
Mattermost General
3.1
LOW
EPSS
0.0%
2025 CWE-639 1 PoC

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration

CVE-2025-11777
Mattermost Web
3.1
LOW
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint

CVE-2025-41436
Mattermost General
3.1
LOW
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

CVE-2025-3611
Mattermost Web
3.1
LOW
EPSS
0.1%
2025 CWE-863 1 PoC

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.

CVE-2025-41423
Mattermost Web
3.1
LOW
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.

CVE-2025-1792
Mattermost Web
3.1
LOW
EPSS
0.1%
2025 CWE-863 1 PoC

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.

CVE-2025-62774
M6a General
3.1
LOW
EPSS
0.0%
2025 CWE-331 1 PoC

On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.

CVE-2025-0503
Mattermost General
3.1
LOW
EPSS
0.4%
2025 CWE-754 1 PoC

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.

CVE-2025-55074
Mattermost General
3.0
LOW
EPSS
0.0%
2025 CWE-1426 1 PoC

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects

CVE-2025-31363
Mattermost General
3.0
LOW
EPSS
0.2%
2025 CWE-1426 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt injection in the AI plugin's Jira tool.

CVE-2025-13352
Mattermost General
3.0
LOW
EPSS
0.1%
2025 CWE-1287 1 PoC

Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.

CVE-2025-30343
OpenSlides General
3.0
LOW
EPSS
0.5%
2025 CWE-24 1 PoC

A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the title of a file or folder as a relative or absolute path (e.g., ../../../etc/passwd), the ZIP archive generated for download converts that title into a path. Depending on the extraction tool used by the user, this might overwrite files locally outside of the chosen directory.

CVE-2025-56558
MQTT server Cloud
3.0
LOW
EPSS
0.0%
2025 CWE-420 1 PoC

The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct values of AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, and device serial number, even if a device (such as a Pure Hot+Cool device) has been removed and is not visible in the supported MyDyson app. This could allow an unexpected actor to obtain control and set the room temperature (up to 37 Celsius) if ownership of the device is transferred without wiping the device. NOTE: the Supplier's position is that this is a potential vulnerability that dates back 4 years

CVE-2025-43718
Poppler General
2.9
LOW
EPSS
0.0%
2025 CWE-674 1 PoC

Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated functions in PDFDoc, with deep recursion in the regex executor (std::__detail::_Executor).