Vulnerability Details CVE-2025-54458
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.3%
CVSS Severity
CVSS v3 Score 5.0
Products affected by CVE-2025-54458
-
cpe:2.3:a:mattermost:confluence:0.1.0
-
cpe:2.3:a:mattermost:confluence:1.0.0
-
cpe:2.3:a:mattermost:confluence:1.1.0
-
cpe:2.3:a:mattermost:confluence:1.2.0
-
cpe:2.3:a:mattermost:confluence:1.3.0
-
cpe:2.3:a:mattermost:confluence:1.4.0