CVE-2025-2475

Unauthorized Bot Login Using Credentials

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.


We have discovered 30 live websites that are affected by CVE-2025-2475.

Run a Free Instant Scan




Affected Software

Product  Mattermost
Category Message Boards
Vulnerable Domains30 live websites (7.23% of Mattermost install base)
Vulnerable Versions
  • from 9.11 through 9.11.9
  • from 10.4 through 10.4.3
  • from 10.5 through 10.5.1
Vulnerable Versions Count6 versions ( 8.96% of all versions)


Common Weakness Enumeration

CWE-303 Incorrect Implementation of Authentication Algorithm



Details

  • Published - Apr 14, 2025
  • Updated - Apr 14, 2025

Credits

  • eAhmed (finder)

Website Distribution by Country

Number of websites using CVE-2025-2475
United States8 websites



Germany4 websites
France2 websites
Japan2 websites
Turkmenistan2 websites
Austria1 websites
Canada1 websites
Switzerland1 websites
Czech Republic1 websites

Website Distribution by TLD

Number of websites using CVE-2025-2475
.com7 websites
.org6 websites
.ru2 websites
.ch1 websites
.de1 websites
.fr1 websites
.info1 websites
.net1 websites
.se1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-2475

Top websites that are affected by CVE-2025-2475. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.************.org Canada*,***,***
*****.****.to Japan**,***,***
****.************.se Sweden**,***,***
**.********.com United States**,***,***
****.*************.fm Netherlands**,***,***
***.********.org United States**,***,***
****.*******.com United States**,***,***
****.******.de Germany**,***,***
**.********.com Turkmenistan**,***,***
**.********.com Turkmenistan**,***,***
See full domain list

FAQ

CVE-2025-2475 is Incorrect Implementation of Authentication Algorithm in Mattermost
A total of 30 websites have been identified as vulnerable to CVE-2025-2475, based on global website indexing conducted by WebTechSurvey.
The Mattermost is affected by the CVE-2025-2475 vulnerability.
Mattermost versions up to and including 10.5.1 are vulnerable to CVE-2025-2475.