Mattermost
Mattermost Confluence: vulnerabilidades y CVE
Mattermost Confluence tiene 14 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-13523 | Media (5.4) | 0.20% | — | 6 feb 2026 | Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary… |
| CVE-2025-8285 | Media (5.3) | 0.20% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create… |
| CVE-2025-54525 | Alta (7.5) | 0.34% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body. |
| CVE-2025-54478 | Media (5.3) | 0.24% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel… |
| CVE-2025-54463 | Alta (7.5) | 0.30% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body. |
| CVE-2025-54458 | Media (5) | 0.21% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the… |
| CVE-2025-53910 | Media (4) | 0.20% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit… |
| CVE-2025-53857 | Baja (3.7) | 0.21% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET… |
| CVE-2025-53514 | Media (5.9) | 0.29% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body. |
| CVE-2025-52931 | Alta (7.5) | 0.34% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body. |
| CVE-2025-49221 | Baja (3.7) | 0.25% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET… |
| CVE-2025-48731 | Media (6.4) | 0.18% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit… |
| CVE-2025-44004 | Alta (7.2) | 0.21% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to… |
| CVE-2025-44001 | Media (4) | 0.21% | — | 11 ago 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get… |