CVE-2025-6226 IDOR in CreatePost API allows for timeboxed message disclosure

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which ...

Continue Reading
CVE-2025-6226 IDOR in CreatePost API allows for timeboxed message disclosure

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which ...

Continue Reading
CVE-2025-6813

creation_timestamp| type| source ---|---|--- 2025-07-18 06:30:40+00:00| seen|...Read More ...

Continue Reading
CVE-2025-3740

creation_timestamp| type| source ---|---|--- 2025-07-18 06:35:41+00:00| seen|...Read More ...

Continue Reading
CVE-2025-7431

creation_timestamp| type| source ---|---|--- 2025-07-18 02:50:29+00:00| seen|...Read More ...

Continue Reading
CVE-2025-7767

creation_timestamp| type| source ---|---|--- 2025-07-18 02:55:29+00:00| seen|...Read More ...

Continue Reading
CVE-2025-6391

creation_timestamp| type| source ---|---|--- 2025-07-18 00:45:27+00:00| seen|...Read More ...

Continue Reading
CVE-2025-7756

creation_timestamp| type| source ---|---|--- 2025-07-18 01:00:46+00:00| seen|...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: