4.3

CVSS3.1

CVE-2025-27571 - Channel metadata visible in archived channels despite configuration setting

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived Channels" configuration when fetching channel metadata of a post from archived channels, which allows authenticated users to access such information when a channel is archived.

πŸ“… Published: April 16, 2025, 7:45 a.m. πŸ”„ Last Modified: Oct. 1, 2025, 6:20 p.m.

2.2

CVSS3.1

CVE-2025-27538 - MFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other Users

Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if those users have no…

πŸ“… Published: April 16, 2025, 7:45 a.m. πŸ”„ Last Modified: Oct. 1, 2025, 6:20 p.m.

3.1

CVSS3.1

CVE-2025-24839 - Unauthorized AI bot activation via Wrangler plugin

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override property to a post via the Wrangler plugin, provide…

πŸ“… Published: April 16, 2025, 7:44 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 2:50 p.m.

6.4

CVSS3.1

CVE-2025-3077 - Betheme <= 28.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custom CSS field in all versions up to, and including, 28.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

πŸ“… Published: April 16, 2025, 7:31 a.m. πŸ”„ Last Modified: April 21, 2026, 9:30 p.m.

6.5

CVSS3.1

CVE-2025-0101 - WAGO: Year 2038 problem

A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart.

πŸ“… Published: April 16, 2025, 7:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2021-47685 -

** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

πŸ“… Published: April 16, 2025, 7:16 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 3:28 p.m.

0.0

CVE-2021-47686 -

** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

πŸ“… Published: April 16, 2025, 7:16 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 3:28 p.m.

0.0

CVE-2021-47687 -

** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

πŸ“… Published: April 16, 2025, 7:16 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 3:28 p.m.

0.0

CVE-2021-47684 -

** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

πŸ“… Published: April 16, 2025, 7:16 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 3:28 p.m.

0.0

CVE-2021-47681 -

** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

πŸ“… Published: April 16, 2025, 7:16 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 3:28 p.m.
Total resulsts: 346617
Page 5523 of 34,662
Β« previous page Β» next page
Filters