Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
We have discovered 30 live websites that are affected by CVE-2025-2475.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 30 live websites (7.23% of Mattermost install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 6 versions ( 8.96% of all versions) |
| 8 websites | |
| 4 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 7 websites |
| .org | 6 websites |
| .ru | 2 websites |
| .ch | 1 websites |
| .de | 1 websites |
| .fr | 1 websites |
| .info | 1 websites |
| .net | 1 websites |
| .se | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.************.org | *,***,*** | ||
| *****.****.to | **,***,*** | ||
| ****.************.se | **,***,*** | ||
| **.********.com | **,***,*** | ||
| ****.*************.fm | **,***,*** | ||
| ***.********.org | **,***,*** | ||
| ****.*******.com | **,***,*** | ||
| ****.******.de | **,***,*** | ||
| **.********.com | **,***,*** | ||
| **.********.com | **,***,*** |
FAQ