Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
CVE ID: CVE-2025-0503
CVSS Base Severity: LOW
CVSS Base Score: 3.1
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Vendor: Mattermost
Product: Mattermost
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.99% (scored less or equal to compared to others)
EPSS Date: 2025-03-15 (when was this score calculated)