Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 0 ~ 6.0.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12689 | 6.5 MEDIUM | DoS in Calls plugin via malformed UTF-8 in WebSocket request |
| CVE-2025-62190 | 4.3 MEDIUM | CSRF Allows Call Initiation and Message Delivery |
| CVE-2025-13324 | 3.7 LOW | Lack of Invalidation of Legacy Remote Cluster Invite Tokens After Confirmation |
| CVE-2025-13321 | 3.3 LOW | Mattermost Desktop App logging sensitive information and fails to clear data on server del |
| CVE-2025-62690 | 3.1 LOW | Open redirect in error page when link opened in new tab |
| CVE-2025-13352 | 3.0 LOW | Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hija |
No comments yet