PT-2025-32581 · WordPress · Mattermost Confluence Plugin

Lorenzo Gallegos

·

Published

2025-07-10

·

Updated

2025-08-20

·

CVE-2025-54463

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Mattermost Confluence Plugin versions prior to 1.5.0
Description: The Mattermost Confluence Plugin does not properly handle unexpected request bodies. Attackers can exploit this to crash the plugin by repeatedly sending invalid request bodies to the server webhook endpoint.
Recommendations: Update Mattermost Confluence Plugin to version 1.5.0 or later.

Fix

DoS

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2025-09761
CVE-2025-54463
GHSA-GJPM-6W34-PPVF
GO-2025-3866
OPENSUSE-SU-2025:15469-1

Affected Products

Mattermost Confluence Plugin