Junglewise Threat Intelligence
CVE-2025-13523: GO-2026-4456 - Mattermost Confluence plugin doesn't properly escape user-controlled display names in HTML template rendering in github.com/mattermost/matte
CVE-2025-13523 · Severity: low · CVSS 3.1 · Published 2026-02-17
Technologies: github.com/mattermost/mattermost-plugin-confluence (Go). Vendors: Go.
Executive brief
Mattermost Confluence plugin doesn't properly escape user-controlled display names in HTML template rendering in github.com/mattermost/mattermost-plugin-confluence
Affected products
- Go github.com/mattermost/mattermost-plugin-confluence