Mattermost Confluence Plugin vulnerabilities

14 known vulnerabilities affecting mattermost/mattermost_confluence_plugin.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM8LOW2

Vulnerabilities

Page 1 of 1
CVE-2025-13523MEDIUMCVSS 5.4fixed in 1.7.02026-02-06
CVE-2025-13523 [HIGH] CWE-79 CVE-2025-13523: Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names i Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's displa
cvelistv5nvd
CVE-2025-54525HIGHCVSS 7.5fixed in 1.5.02025-08-11
CVE-2025-54525 [HIGH] CWE-1287 CVE-2025-54525: Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows att Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.
cvelistv5nvd
CVE-2025-44004HIGHCVSS 7.2fixed in 1.5.02025-08-11
CVE-2025-44004 [HIGH] CWE-306 CVE-2025-44004: Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Matt Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.
cvelistv5nvd
CVE-2025-52931HIGHCVSS 7.5fixed in 1.5.02025-08-11
CVE-2025-52931 [HIGH] CWE-754 CVE-2025-52931: Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows att Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.
cvelistv5nvd
CVE-2025-54463HIGHCVSS 7.5fixed in 1.5.02025-08-11
CVE-2025-54463 [MEDIUM] CWE-754 CVE-2025-54463: Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows att Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.
cvelistv5nvd
CVE-2025-48731MEDIUMCVSS 6.4fixed in 1.5.02025-08-11
CVE-2025-48731 [MEDIUM] CWE-862 CVE-2025-48731: Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint.
cvelistv5nvd
CVE-2025-53910MEDIUMCVSS 4.0fixed in 1.5.02025-08-11
CVE-2025-53910 [MEDIUM] CWE-862 CVE-2025-53910: Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel whi Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.
cvelistv5nvd
CVE-2025-44001MEDIUMCVSS 4.0fixed in 1.5.02025-08-11
CVE-2025-44001 [MEDIUM] CWE-862 CVE-2025-44001: Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel whi Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.
cvelistv5nvd
CVE-2025-54458MEDIUMCVSS 5.0fixed in 1.5.02025-08-11
CVE-2025-54458 [MEDIUM] CWE-862 CVE-2025-54458: Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.
cvelistv5nvd
CVE-2025-54478MEDIUMCVSS 5.3fixed in 1.5.02025-08-11
CVE-2025-54478 [HIGH] CWE-306 CVE-2025-54478: Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Matte Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.
cvelistv5nvd
CVE-2025-8285MEDIUMCVSS 5.3fixed in 1.5.02025-08-11
CVE-2025-8285 [MEDIUM] CWE-862 CVE-2025-8285: Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel whi Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.
cvelistv5nvd
CVE-2025-53514MEDIUMCVSS 5.9fixed in 1.5.02025-08-11
CVE-2025-53514 [MEDIUM] CWE-754 CVE-2025-53514: Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows att Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.
cvelistv5nvd
CVE-2025-49221LOWCVSS 3.7fixed in 1.5.02025-08-11
CVE-2025-49221 [LOW] CWE-862 CVE-2025-49221: Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Matte Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.
cvelistv5nvd
CVE-2025-53857LOWCVSS 3.7fixed in 1.5.02025-08-11
CVE-2025-53857 [LOW] CWE-862 CVE-2025-53857: Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel whi Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.
cvelistv5nvd