VYPR

Confluence

by Mattermost

CVEs (14)

  • CVE-2025-13523HigFeb 6, 2026
    risk 0.50cvss 7.7epss 0.00

    Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially…

  • CVE-2025-54525HigAug 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.

  • CVE-2025-52931HigAug 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.

  • CVE-2025-54478HigAug 11, 2025
    risk 0.47cvss 7.2epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.

  • CVE-2025-44004HigAug 11, 2025
    risk 0.47cvss 7.2epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.

  • CVE-2025-48731MedAug 11, 2025
    risk 0.42cvss 6.4epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint.

  • CVE-2025-54463MedAug 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.

  • CVE-2025-53514MedAug 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.

  • CVE-2025-54458MedAug 11, 2025
    risk 0.33cvss 5.0epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.

  • CVE-2025-8285MedAug 11, 2025
    risk 0.26cvss 4.0epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.

  • CVE-2025-53910MedAug 11, 2025
    risk 0.26cvss 4.0epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.

  • CVE-2025-44001MedAug 11, 2025
    risk 0.26cvss 4.0epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.

  • CVE-2025-53857LowAug 11, 2025
    risk 0.24cvss 3.7epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.

  • CVE-2025-49221LowAug 11, 2025
    risk 0.24cvss 3.7epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.