Mattermost fails to properly enforce access control restrictions for System Manager roles

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated us ...

Continue Reading
CVE-2025-48946

creation_timestamp| type| source ---|---|--- 2025-05-30 20:20:02+00:00| seen|...Read More ...

Continue Reading
Mattermost fails to properly enforce access controls for guest users

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing a ...

Continue Reading
CVE-2025-5357

creation_timestamp| type| source ---|---|--- 2025-05-30 18:16:40+00:00| seen|...Read More ...

Continue Reading
CVE-2025-48949 Navidrome allows SQL Injection via role parameter

Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the role parameter within the API en ...

Continue Reading
CVE-2025-48942 vLLM DOS: Remotely kill vllm over http with invalid JSON schema

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema as a Guided Param kil ...

Continue Reading
CVE-2025-48887

creation_timestamp| type| source ---|---|--- 2025-05-30 18:17:24+00:00| seen|...Read More ...

Continue Reading
CVE-2025-5358

creation_timestamp| type| source ---|---|--- 2025-05-30 18:17:03+00:00| seen|...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: