Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint
We have discovered 74 live websites that are affected by CVE-2025-10545.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 74 live websites (19% of Mattermost install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 8 versions ( 11% of all versions) |
| 12 websites | |
| 28 websites | |
| 9 websites | |
| 8 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites |
| .com | 17 websites |
| .org | 17 websites |
| .de | 10 websites |
| .ru | 4 websites |
| .fr | 3 websites |
| .net | 3 websites |
| .be | 2 websites |
| .co.uk | 2 websites |
| .ca | 1 websites |
| .co | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | ***,*** | ||
| ****.*******.org | *,***,*** | ||
| **.*****.re | *,***,*** | ||
| ***********.ru | *,***,*** | ||
| ****.*******.com | *,***,*** | ||
| ****.*********.org | *,***,*** | ||
| *************.org | *,***,*** | ||
| ****************.de | *,***,*** | ||
| ******.de | *,***,*** | ||
| *****.*************.org | *,***,*** |
FAQ