mattermost confluence の CVE(14 件)

CVE 件数: 14 CPE versions: View versions table

概要

本ページは mattermost confluence に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。

表示中 114 / 14 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-13523 Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermost Advisory ID: MMSA-2025-00557 [email protected] 7.7 0.01% 2026-02-06 2026-02-24
CVE-2025-8285 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint. [email protected] 4.0 0.21% 2025-08-11 2025-09-24
CVE-2025-54525 Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body. [email protected] 7.5 0.44% 2025-08-11 2025-09-24
CVE-2025-54478 Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint. [email protected] 7.2 0.27% 2025-08-11 2025-09-24
CVE-2025-54463 Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body. [email protected] 5.9 0.33% 2025-08-11 2025-09-24
CVE-2025-54458 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint. [email protected] 5.0 0.18% 2025-08-11 2025-09-25
CVE-2025-53910 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint. [email protected] 4.0 0.21% 2025-08-11 2025-09-25
CVE-2025-53857 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint. [email protected] 3.7 0.20% 2025-08-11 2025-09-25
CVE-2025-53514 Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body. [email protected] 5.9 0.33% 2025-08-11 2025-09-25
CVE-2025-52931 Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body. [email protected] 7.5 0.44% 2025-08-11 2025-09-25
CVE-2025-49221 Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint. [email protected] 3.7 0.05% 2025-08-11 2025-09-24
CVE-2025-48731 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint. [email protected] 6.4 0.19% 2025-08-11 2025-09-25
CVE-2025-44004 Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint. [email protected] 7.2 0.26% 2025-08-11 2025-09-25
CVE-2025-44001 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint. [email protected] 4.0 0.20% 2025-08-11 2025-09-25
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence