Confluence
Vendor:
First CVE: Aug 11, 2025 · Active for under a year
14
Total CVEs
More Total CVEs than 91% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Confluence over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 11, 2025
11 months ago
Most Recent CVE
Feb 6, 2026
168 days ago
CVE Severity & Scoring
Confluence14 CVEs
14%
57%
29%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (64.3%)
High5 (35.7%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low3 (21.4%)
High0 (0.0%)
None11 (78.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54525HIGH Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpo | Aug 11, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-54463HIGH Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an i | Aug 11, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-52931HIGH Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpo | Aug 11, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-44004HIGH Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without | Aug 11, 2025 | 7.2 | 23 | NO | NO |
CVE-2025-53514MEDIUM Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an i | Aug 11, 2025 | 5.9 | 21 | NO | NO |
CVE-2025-48731MEDIUM Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the u | Aug 11, 2025 | 6.4 | 21 | NO | NO |
CVE-2025-13523MEDIUM Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malic | Feb 6, 2026 | 5.4 | 20 | NO | NO |
CVE-2025-8285MEDIUM Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the | Aug 11, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-54478MEDIUM Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscripti | Aug 11, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-54458MEDIUM Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the | Aug 11, 2025 | 5.0 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Confluence
Top CWEs
Versions
No cataloged versions.