In Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, and 10.9.x <= 10.9.3 a medium severity vulnerability CVE-2025-8402 was detected. This vulnerability allows a System Admin to crash the server via the bulk import feature. To address this issue, users should upgrade Mattermost to versions 10.8.4, 10.5.9, 10.9.4, 10.10.1 or 9.11.18. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-8402.
Read more CommunicationIn Mattermost versions 10.8.x through 10.8.3, 10.5.x through 10.5.8, 9.11.x through 9.11.17, and 10.9.x through 10.9.2 a medium severity vulnerability CVE-2025-8023 was detected. This vulnerability allows a System Admin to perform path traversal attacks by using malicious path components, which could lead to malicious file placement outside of intended directories. To address this issue, users should upgrade Mattermost to versions 10.8.4, 10.5.9, 9.11.18 or 10.9.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-8023.
Read more CommunicationIn Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, and 10.9.x <= 10.9.3 a medium severity vulnerability CVE-2025-6465 was detected. This vulnerability allows a user with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs. To address this issue, users should upgrade Mattermost to versions 10.8.4, 10.5.9, 10.9.4 or 10.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6465.
Read more CommunicationIn Mattermost Server versions 10.5.x through 10.5.9 utilizing the Agents plugin a low severity vulnerability CVE-2025-47700 was detected. This vulnerability allows an attacker to trick users into clicking malicious links via post actions. To address this issue, users should upgrade Mattermost plugins to versions 10.10.0, 10.5.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-47700.
Read more CommunicationIn Mattermost versions 10.5.x <= 10.5.8 and 9.11.x <= 9.11.17 a low severity vulnerability CVE-2025-53971 was detected. This vulnerability allows a Team Admin to demote a Team Member to a Guest via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint. To address this issue, users should upgrade Mattermost to versions 10.10.0, 10.5.9, 9.11.18 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53971.
Read more CommunicationIn Mattermost versions 10.5.x <= 10.5.8 a low severity vulnerability CVE-2025-49810 was detected. This vulnerability allows a user to read a thread via AI posts. To address this issue, users should upgrade Mattermost to versions 10.10.0, 10.5.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49810.
Read more CommunicationIn Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 and 10.9.x <= 10.9.2 a medium severity vulnerability CVE-2025-47870 was detected. This vulnerability allows a Team Admin with no member invite privileges to get the team's invite ID. To address this issue, users should upgrade Mattermost to versions 10.10.0, 10.8.4, 10.5.9, 9.11.18, 10.9.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-47870.
Read more CommunicationIn Discourse versions before 3.4.7 and from 3.5.0.beta1 to before 3.5.0.beta.8 a high severity vulnerability CVE-2025-53102 was detected. This vulnerability allows attackers to reuse a 2FA security key challenge after login, which increases the risk of unauthorized access. To address this issue, users should upgrade Discourse to versions 3.4.7, 3.5.0.beta.8 or later. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-53102.
Read more CommunicationIn Mattermost versions 10.8.x up to 10.8.1, 10.7.x up to 10.7.3, 10.5.x up to 10.5.7 and 9.11.x up to 9.11.16 a medium severity vulnerability CVE-2025-6233 was detected. This vulnerability allows system administrators to read arbitrary system files via path traversal due to improper sanitization of file attachment input paths in the bulk import JSONL file. To address this issue, users should upgrade Mattermost to versions 10.9.0, 10.8.2, 10.7.4, 10.5.8, 9.11.17 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6233.
Read more Communication