<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 08:18:01 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-53857 — Lack of Authorization on Get Channel Subscriptions for Autocomplete in Mattermost Confluence Plugin</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-53857</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mattermost Confluence Plugin&lt;/p&gt;
&lt;p&gt;Mattermost Confluence Plugin version &amp;lt;1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mattermost Confluence Plugin&lt;/p&gt;
&lt;p&gt;Mattermost Confluence Plugin version &amp;lt;1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-53857</guid>
    </item>
  </channel>
</rss>
