HTML Injection Vulnerability in Mattermost Confluence Plugin
CVE-2025-13523

7.7HIGH

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
6 February 2026

What is CVE-2025-13523?

The Mattermost Confluence plugin prior to version 1.7.0 contains a flaw that improperly escapes user-controlled display names during HTML template rendering. This vulnerability allows authenticated Confluence users who have malicious display names to execute arbitrary JavaScript code in the browsers of unsuspecting victims. By sending a specially crafted OAuth2 connection link, which renders the attacker's unescaped display name in the victim's browser, the attacker can exploit this vulnerability to perform various malicious actions. For detailed security updates, please refer to the Mattermost advisory at MMSA-2025-00557.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Mattermost Confluence Plugin 0 < 1.7.0

Mattermost Confluence Plugin 1.7.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daw10
.