📦 Confluence

by Mattermost

🔍 What is Confluence?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-13523

HIGH CVSS 7.7 Feb 6, 2026

This cross-site scripting (XSS) vulnerability in Mattermost's Confluence plugin allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers. A...

CVE-2025-54478

HIGH CVSS 7.2 Aug 11, 2025

The Mattermost Confluence Plugin before version 1.5.0 has an authentication bypass vulnerability that allows unauthenticated attackers to edit channel subscriptions via API calls. This affects organiz...

CVE-2025-52931

HIGH CVSS 7.5 Aug 11, 2025

The Mattermost Confluence Plugin before version 1.5.0 contains an improper input validation vulnerability that allows attackers to crash the plugin by sending malformed requests to the update channel ...

CVE-2025-44004

HIGH CVSS 7.2 Aug 11, 2025

The Mattermost Confluence Plugin before version 1.5.0 has an authorization bypass vulnerability that allows attackers to create unauthorized channel subscriptions via API calls. This affects organizat...

CVE-2025-54463

MEDIUM CVSS 5.9 Aug 11, 2025

The Mattermost Confluence Plugin before version 1.5.0 contains an improper input validation vulnerability that allows attackers to crash the plugin by sending malformed requests to the server webhook ...

CVE-2025-53514

MEDIUM CVSS 5.9 Aug 11, 2025

The Mattermost Confluence Plugin before version 1.5.0 contains an improper input validation vulnerability that allows attackers to crash the plugin by sending malformed requests to its webhook endpoin...

CVE-2025-53910

MEDIUM CVSS 4.0 Aug 11, 2025

The Mattermost Confluence Plugin vulnerability allows attackers to create unauthorized channel subscriptions via API calls. This affects organizations using Mattermost with the Confluence plugin befor...

CVE-2025-54458

MEDIUM CVSS 5.0 Aug 11, 2025

The Mattermost Confluence Plugin before version 1.5.0 has an authorization bypass vulnerability where it fails to verify user permissions when creating Confluence space subscriptions. Attackers can su...

CVE-2025-44001

MEDIUM CVSS 4.0 Aug 11, 2025

The Mattermost Confluence Plugin before version 1.5.0 has an authorization bypass vulnerability where attackers can retrieve channel subscription details without proper access permissions. This affect...