Vulnerability Details CVE-2025-12756
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.9%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2025-12756
-
cpe:2.3:a:mattermost:mattermost_server:10.11.0
-
cpe:2.3:a:mattermost:mattermost_server:10.11.1
-
cpe:2.3:a:mattermost:mattermost_server:10.11.2
-
cpe:2.3:a:mattermost:mattermost_server:10.11.3
-
cpe:2.3:a:mattermost:mattermost_server:10.11.4
-
cpe:2.3:a:mattermost:mattermost_server:10.12.0
-
cpe:2.3:a:mattermost:mattermost_server:10.12.1
-
cpe:2.3:a:mattermost:mattermost_server:10.5.0
-
cpe:2.3:a:mattermost:mattermost_server:10.5.1
-
cpe:2.3:a:mattermost:mattermost_server:10.5.10
-
cpe:2.3:a:mattermost:mattermost_server:10.5.11
-
cpe:2.3:a:mattermost:mattermost_server:10.5.12
-
cpe:2.3:a:mattermost:mattermost_server:10.5.2
-
cpe:2.3:a:mattermost:mattermost_server:10.5.3
-
cpe:2.3:a:mattermost:mattermost_server:10.5.4
-
cpe:2.3:a:mattermost:mattermost_server:10.5.5
-
cpe:2.3:a:mattermost:mattermost_server:10.5.6
-
cpe:2.3:a:mattermost:mattermost_server:10.5.7
-
cpe:2.3:a:mattermost:mattermost_server:10.5.8
-
cpe:2.3:a:mattermost:mattermost_server:10.5.9
-
cpe:2.3:a:mattermost:mattermost_server:11.0.0
-
cpe:2.3:a:mattermost:mattermost_server:11.0.1
-
cpe:2.3:a:mattermost:mattermost_server:11.0.2