CVE-2024-1949Low· 2.6▾ SunlitMattermost race condition
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.
github.com/mattermost/mattermost/server/v8 >= 9.0.0, < 9.4.2github.com/mattermost/mattermost/server/v8 < 8.1.9Upgrade to a patched release:
github.com/mattermost/mattermost/server/v8 9.4.2github.com/mattermost/mattermost/server/v8 8.1.9Connected by shared product, vendor, weakness, or advisory.
CVE-2023-6202Medium· 4.3Mattermost Improper Access Control vulnerability
CVE-2025-22445Low· 3.5Mattermost has Improper Check for Unusual or Exceptional Conditions
CVE-2024-46872Medium· 4.6Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
CVE-2024-47401Medium· 4.3Mattermost Server vulnerable to application crash from attacker-generated large response
CVE-2024-10241Medium· 4.3Mattermost Server allows user to get private channel names
CVE-2025-2475Medium· 5.4Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm