| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Confluence products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-41103 | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. | 9.1 |
| 568 |
| Neutral |
| No |
| Yes |
| CVE-2026-21579 | Information Disclosure in Confluence Data Center | 7.5 | 450 | Neutral | No | Yes |
| CVE-2026-21577 | DoS (Denial of Service) in Confluence Data Center | 6.5 | 209 | Neutral | No | Yes |
| CVE-2025-8285 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call... | 5.3 | 188 | Neutral | No | Yes |
| CVE-2025-54525 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid ... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2025-54478 | Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to ... | 5.3 | 253 | Neutral | No | Yes |
| CVE-2025-54463 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body. | 7.5 | 386 | Neutral | No | Yes |
| CVE-2025-54458 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have ... | 5.0 | 175 | Neutral | No | Yes |
| CVE-2025-53910 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API ca... | 4.0 | 168 | Neutral | No | Yes |
| CVE-2025-53857 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API... | 3.7 | 167 | Neutral | No | Yes |
| CVE-2025-53514 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body. | 5.9 | 155 | Neutral | No | Yes |
| CVE-2025-52931 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid ... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2025-49221 | Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API... | 3.7 | 167 | Neutral | No | Yes |
| CVE-2025-48731 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have ac... | 6.4 | 262 | Neutral | No | Yes |
| CVE-2025-44004 | Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization... | 7.2 | 459 | Neutral | No | Yes |
| CVE-2025-44001 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API... | 4.0 | 168 | Neutral | No | Yes |
| CVE-2025-27604 | XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might ... | 7.5 | 450 | Neutral | No | Yes |
| CVE-2025-22166 | DoS (Denial of Service) in Confluence Data Center28 Oct 2025UPDATE: This fix was released and added to the October Bulletin post-publication.It will be included in the November Bulletin as well for ge... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2025-13523 | Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names t... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2024-48942 | The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidati... | 5.9 | 155 | Neutral | No | Yes |