Skip to main content

Vendor/product archive

mattermost / confluence CVEs

Beta · best-effort

14 CVEs tagged to mattermost / confluence0 Critical, 5 High, 7 Medium, 2 Low, 0 Unrated.

CVE-2025-13523

Published Feb 6, 2026

Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with mali…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-8285

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54525

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54478

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscript…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54463

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54458

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53910

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to t…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53857

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access t…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-53514

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52931

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49221

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription de…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-48731

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-44004

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-44001

Published Aug 11, 2025

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access t…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1