23 Total CVEs
23 AI Analyzed
0 CISA KEV
2 Critical

Profile

0% ended up actively exploited 0 of 23 added to CISA KEV
9% rated critical (CVSS 9.0+) 2 critical, 21 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

17 CVEs in the last 12 months

Products

  • Mattermost17
  • Mattermost Confluence Plugin5
  • Focalboard1

3 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-23 of 23 CVEs
CVE-2025-12421
Analyzed
9.9
Mattermost Mattermost

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code...

2025-11-28
Full analysis →
CVE-2025-12419
Analyzed
9.9
Mattermost Mattermost

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during Op...

2025-11-28
Full analysis →