3.1
CVE-2025-3611 - Improper Access Control in Mattermost allows System Managers to view team details despite role restβ¦
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team eβ¦
5.4
CVE-2025-3230 - Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previoβ¦
4.2
CVE-2025-2571 - Google OAuth Authentication Bypass for Converted Bot Accounts
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
3.1
CVE-2025-1792 - Improper Access Control in Mattermost Channel Member API
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
8.7
CVE-2025-0602 - Stored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovatβ¦
A stored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2025-4983 - Stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manaβ¦
A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2025-4984 - Stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Managerβ¦
A stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2025-4985 - Stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manaβ¦
A stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2025-4986 - Stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from β¦
A stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2025-4988 - Stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Opβ¦
A stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.