Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 10.11.0 ~ 10.11.6 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12689 | 6.5 MEDIUM | DoS in Calls plugin via malformed UTF-8 in WebSocket request |
| CVE-2025-62190 | 4.3 MEDIUM | CSRF Allows Call Initiation and Message Delivery |
| CVE-2025-13326 | 3.9 LOW | Mattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App Store |
| CVE-2025-13324 | 3.7 LOW | Lack of Invalidation of Legacy Remote Cluster Invite Tokens After Confirmation |
| CVE-2025-13321 | 3.3 LOW | Mattermost Desktop App logging sensitive information and fails to clear data on server del |
| CVE-2025-62690 | 3.1 LOW | Open redirect in error page when link opened in new tab |
No comments yet