Skip to content
Noroxi

eAhmed

8 credited records · 4 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • GitHub OAuth Scope Validation

    MediumCVSS 5.4No exploitEPSS 0%

    mattermost · mattermost serverMay 22, 2026

  • CVE-2026-3473
    28Monitor

    Improper file ownership validation in the Boards API allows unauthorised file access

    HighCVSS 7.1No exploitEPSS 0%

    mattermost · mattermost serverMay 22, 2026

  • CVE-2026-6342
    17Monitor

    Group prefix matching bypass for subscriptions

    MediumCVSS 4.3No exploitEPSS 0%

    mattermost · mattermost serverMay 18, 2026

  • CVE-2026-6341
    17Monitor

    Incomplete group locking implementation

    MediumCVSS 4.3No exploitEPSS 0%

    mattermost · mattermost serverMay 18, 2026

  • CVE-2025-3230
    21Monitor

    Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server

    MediumCVSS 5.4No exploitEPSS 0%

    mattermost · mattermost serverMay 30, 2025

  • CVE-2025-2571
    16Monitor

    Google OAuth Authentication Bypass for Converted Bot Accounts

    MediumCVSS 4.2No exploitEPSS 0%

    mattermost · mattermost serverMay 30, 2025

  • CVE-2025-2475
    21Monitor

    Unauthorized Bot Login Using Credentials

    MediumCVSS 5.4No exploitEPSS 0%

    mattermost · mattermost serverApr 14, 2025

  • CVE-2025-1412
    35Monitor

    Session Persistence After User-to-Bot Conversion

    HighCVSS 8.8No exploitEPSS 0%

    mattermost · mattermost serverFeb 24, 2025