In Mattermost versions 10.12.x through 10.12.1, 10.11.x through 10.11.4, 10.5.x through 10.5.12, and 11.0.x through 11.0.3 a critical severity vulnerability CVE-2025-12419 was detected. This vulnerability allows an authenticated attacker with team creation privileges to take over a user account by manipulating authentication data during the OAuth completion flow. This is due to improper validation of OAuth state tokens during OpenID Connect authentication. The vulnerability requires email verification to be disabled (default: disabled), OAuth/OpenID Connect to be enabled, and the attacker to control two users in the SSO system, with one user never having logged into Mattermost. To address this issue, users should upgrade Mattermost to versions 10.12.2, 10.11.5, 10.5.13, and 11.0.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12419.
Read more CommunicationIn SKT PayPal for WooCommerce plugin for WordPress versions up to and including 1.4 a high severity vulnerability CVE-2025-7820 was detected. This vulnerability allows unauthenticated attackers to bypass payment processing by exploiting the plugin’s enforcement of client-side controls instead of server-side controls. As a result, attackers can make confirmed purchases without actually paying. To address this issue, users should upgrade to a fixed version once available. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-7820.
Read more CMSIn GitLab CE/EE versions 8.3 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a medium severity vulnerability CVE-2025-7449 was detected. This vulnerability allows authenticated users with specific permissions to cause a denial of service (DoS) condition through HTTP response processing. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-7449.
Read more Developer ToolsIn GitLab CE/EE versions 17.10 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a high severity vulnerability CVE-2025-12571 was detected. This vulnerability allows unauthenticated users to cause a denial of service (DoS) by sending specially crafted requests containing malicious JSON payloads. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12571.
Read more Developer ToolsIn GitLab EE versions 13.7 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a medium severity vulnerability CVE-2025-6195 was detected. This vulnerability could allow authenticated users to view information from security reports under certain configuration conditions. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6195.
Read more Developer ToolsIn GitLab CE/EE versions 13.2 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a low severity vulnerability CVE-2025-13611 was detected. This vulnerability allows authenticated users with access to certain logs to obtain sensitive tokens under specific conditions due to improper handling of sensitive information in log files. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13611.
Read more Developer ToolsIn GitLab CE/EE versions 18.3 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a medium severity vulnerability CVE-2025-12653 was detected. This vulnerability could allow unauthenticated users to join arbitrary organizations by manipulating headers in certain requests under specific conditions. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12653.
Read more Developer ToolsIn the Webform Multiple File Upload module for Drupal 7.x a high severity vulnerability CVE-2025-12848 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in a victim’s browser by uploading a file with a malicious filename when file type validation is disabled on a Webform Multifile field. The issue originates from a third-party library used by the module. To address this issue, users should update the module to version 7.x-1.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12848.
Read more CMSIn OpenSearch versions prior to 3.2.0 a high severity vulnerability CVE-2025-9624 was detected. This vulnerability allows attackers to cause a denial of service (DoS) by submitting complex query_string inputs that trigger excessive resource consumption. To address this issue, users should upgrade OpenSearch to version 3.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9624.
Read more Data Analytics