<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:39:16 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0888 — De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Elles permettent à un attaquant de provoq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0888</link>
      <description>certfr-2025-avi-0888</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0888</guid>
    </item>
    <item>
      <title>EUVD-2026-260750</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260750</link>
      <description>EUVD-2026-260750</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260750</guid>
    </item>
    <item>
      <title>fkie_cve-2025-11777</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-11777</link>
      <description>&lt;p&gt;Mattermost versions 10.11.x &amp;lt;= 10.11.3, 10.5.x &amp;lt;= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mattermost versions 10.11.x &amp;lt;= 10.11.3, 10.5.x &amp;lt;= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-11777</guid>
    </item>
    <item>
      <title>GHSA-mqcj-8c2g-h97q — Mattermost Incorrect Authorization vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mqcj-8c2g-h97q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/mattermost/mattermost-server, Go: github.com/mattermost/mattermost/server/v8, Go: github.com/mattermost/mattermost, Go: github.com/mattermost/mattermost-server/v5, Go: github.com/mattermost/mattermost-server/v6&lt;/p&gt;
&lt;p&gt;Mattermost versions 10.11.x &amp;lt;= 10.11.3, 10.5.x &amp;lt;= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API, which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/mattermost/mattermost-server, Go: github.com/mattermost/mattermost/server/v8, Go: github.com/mattermost/mattermost, Go: github.com/mattermost/mattermost-server/v5, Go: github.com/mattermost/mattermost-server/v6&lt;/p&gt;
&lt;p&gt;Mattermost versions 10.11.x &amp;lt;= 10.11.3, 10.5.x &amp;lt;= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API, which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mqcj-8c2g-h97q</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2315 — Mattermost Server und Mobile: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2315</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mattermost Server und Mobile ausnutzen, um Informationen offenzulegen oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mattermost Server und Mobile ausnutzen, um Informationen offenzulegen oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2315</guid>
    </item>
  </channel>
</rss>
