6.2

CVSS4.0

CVE-2025-3261 - Stored Cross-Site Scripting (XSS) in ThingsBoard

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if tโ€ฆ

๐Ÿ“… Published: Nov. 27, 2025, 6:11 p.m. ๐Ÿ”„ Last Modified: Nov. 27, 2025, 6:11 p.m.

9.9

CVSS3.1

CVE-2025-12421 - Account Takeover via Code Exchange Endpoint

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email aโ€ฆ

๐Ÿ“… Published: Nov. 27, 2025, 5:47 p.m. ๐Ÿ”„ Last Modified: Nov. 27, 2025, 5:47 p.m.

4.3

CVSS3.1

CVE-2025-12559 - Information Disclosure in Common Teams API

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

๐Ÿ“… Published: Nov. 27, 2025, 4:36 p.m. ๐Ÿ”„ Last Modified: Nov. 27, 2025, 4:36 p.m.

9.9

CVSS3.1

CVE-2025-12419 - Account takeover on OAuth/OpenID-enabled servers

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authโ€ฆ

๐Ÿ“… Published: Nov. 27, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 27, 2025, 6:15 p.m.

0.0

CVE-2025-13758 -

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

๐Ÿ“… Published: Nov. 27, 2025, 3:30 p.m. ๐Ÿ”„ Last Modified: Nov. 27, 2025, 3:30 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri ร‡ilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genรง

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali ฤฐltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here