Mattermost Confluence Plugin是美国Mattermost公司的一个插件。 Mattermost Confluence Plugin 1.5.0之前版本存在安全漏洞,该漏洞源于未验证用户身份,可能导致访问订阅详情。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost Confluence Plugin | 0 ~ 1.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-52931 | 7.5 HIGH | Unexpected input to Update Channel Subscription endpoint causes DoS in Mattermost Confluen |
| CVE-2025-54525 | 7.5 HIGH | Unexpected input to Create Channel Subscription endpoint causes DoS in Mattermost Confluen |
| CVE-2025-44004 | 7.2 HIGH | Unauthenticated Channel Subscription Creation in Mattermost Confluence Plugin |
| CVE-2025-54478 | 7.2 HIGH | Unauthenticated Channel Subscription Edit in Mattermost Confluence Plugin |
| CVE-2025-48731 | 6.4 MEDIUM | Unauthorized Subscription Edit to Confluence Space in Mattermost Confluence Plugin |
| CVE-2025-53514 | 5.9 MEDIUM | Unexpected Input to Server Webhook endpoint Causes DoS in Mattermost Confluence Plugin |
| CVE-2025-54463 | 5.9 MEDIUM | Unexpected Input to Cloud Webhook endpoint Causes DoS in Mattermost Confluence Plugin |
| CVE-2025-54458 | 5.0 MEDIUM | Unauthorized Subscription Creation to Confluence Space in Mattermost Confluence Plugin |
| CVE-2025-44001 | 4.0 MEDIUM | Unauthorized Channel Subscription Read in Mattermost Confluence Plugin |
| CVE-2025-53910 | 4.0 MEDIUM | Unauthorized Channel Subscription Edit in Mattermost Confluence Plugin |
| CVE-2025-8285 | 4.0 MEDIUM | Unauthorized Channel Subscription Creation in Mattermost Confluence Plugin |
| CVE-2025-53857 | 3.7 LOW | Lack of Authorization on Get Channel Subscriptions for Autocomplete in Mattermost Confluen |
No comments yet