CVE-2025-13523: Mattermost Confluence
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermost Advisory ID: MMSA-2025-00557
Affected products
- Mattermost Confluence: from 1.0.0, before 1.7.0 (fixed in 1.7.0)
Published 2026-02-06. Last modified 2026-06-17.