Description

Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermost Advisory ID: MMSA-2025-00557

INFO

Published Date :

2026-02-06T15:52:31.003Z

Last Modified :

2026-02-06T16:23:06.496Z

Source :

Mattermost
AFFECTED PRODUCTS

The following products are affected by CVE-2025-13523 vulnerability.

Vendors Products
Mattermost
  • Confluence
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-13523.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact