← Back

Confluence

confluence

Vendor: Mattermost • 14 CVEs

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mattermost
1Confluence
Jun 17, 2026
Feb 6, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary...Show more
Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermost Advisory ID: MMSA-2025-00557Show less
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create chann...Show more
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.Show less
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel sub...Show more
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.Show less
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the cr...Show more
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.Show less
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
4.0 MEDIUM· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit chann...Show more
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.Show less
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET aut...Show more
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.Show less
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscri...Show more
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.Show less
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
6.4 MEDIUM· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit su...Show more
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint.Show less
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the...Show more
Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.Show less
1Mattermost
1Confluence
Jun 17, 2026
Aug 11, 2025
N/A· v4
4.0 MEDIUM· v3
N/A· v2
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Cha...Show more
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.Show less