4.3

CVSS3.1

CVE-2026-4265 - Guest user can upload files without permission across teams

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a team where they have permission and reusing the file…

📅 Published: March 16, 2026, 12:07 p.m. 🔄 Last Modified: March 18, 2026, 5:41 p.m.

4.3

CVSS3.1

CVE-2026-25783 - Denial of service via malformed User-Agent header in getBrowserVersion

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586

📅 Published: March 16, 2026, 12:04 p.m. 🔄 Last Modified: March 18, 2026, 6:11 p.m.

7.5

CVSS3.1

CVE-2026-24458 - DoS attack via login attempts with multi-megabyte passwords

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Mattermost Advisory ID: MMSA-2026-00587

📅 Published: March 16, 2026, 12:02 p.m. 🔄 Last Modified: March 18, 2026, 6:14 p.m.

6.9

CVSS4.0

CVE-2026-4237 - itsourcecode Free Hotel Reservation System index.php sql injection

A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports/index.php. Executing a manipulation of the argument Home can lead to sql injection. The attack may be performed from remote. The exploit has been pub…

📅 Published: March 16, 2026, 12:02 p.m. 🔄 Last Modified: March 16, 2026, 2:54 p.m.

6.6

CVSS3.1

CVE-2026-2462 - Admin RCE via Malicious Plugin Upload on CI Test Instances

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS an…

📅 Published: March 16, 2026, noon 🔄 Last Modified: March 18, 2026, 6:31 p.m.

4.3

CVSS3.1

CVE-2026-2578 - Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read Posts

Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579

📅 Published: March 16, 2026, 11:58 a.m. 🔄 Last Modified: March 18, 2026, 5:42 p.m.

6.9

CVSS4.0

CVE-2025-69246 - Lack of bruteforce protection in Raytha CMS

Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fixed in version 1.4.6.

📅 Published: March 16, 2026, 11:54 a.m. 🔄 Last Modified: March 16, 2026, 7:21 p.m.

5.1

CVSS4.0

CVE-2025-69245 - Reflected XSS in Raytha CMS

Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by the authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue was fixed in 1.4.6.

📅 Published: March 16, 2026, 11:54 a.m. 🔄 Last Modified: March 16, 2026, 7:22 p.m.

6.9

CVSS4.0

CVE-2025-69243 - User enumeration in Raytha CMS

Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. This issue was fixed in version 1.5.0.

📅 Published: March 16, 2026, 11:54 a.m. 🔄 Last Modified: March 16, 2026, 7:26 p.m.

5.1

CVSS4.0

CVE-2025-69242 - Reflected XSS in Raytha CMS

Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue was fixed in version 1.4.6.

📅 Published: March 16, 2026, 11:54 a.m. 🔄 Last Modified: March 16, 2026, 7:27 p.m.
Total resulsts: 338888
Page 71 of 33,889
« previous page » next page
Filters