CVE-2025-14273

Mattermost Jira plugin user spoofing enables Jira request forgery.

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST requests to the Jira server via crafted plugin payloads that spoof the user ID and inject arbitrary issue key paths. Mattermost Advisory ID: MMSA-2025-00555


We have discovered 67 live websites that are affected by CVE-2025-14273.

Run a Free Instant Scan




Affected Software

Product  Mattermost
Category Message Boards
Vulnerable Domains67 live websites (16% of Mattermost install base)
Vulnerable Versions
  • from 10.11 through 10.11.7
  • from 10.12 through 10.12.3
  • from 11 through 11.0.5
  • from 11.1 through 11.1
Vulnerable Versions Count11 versions ( 16% of all versions)


Common Weakness Enumeration

CWE-303 Incorrect Implementation of Authentication Algorithm



Details

  • Published - Dec 22, 2025
  • Updated - Dec 22, 2025

Credits

  • Juho Forsén (finder)

Website Distribution by Country

Number of websites using CVE-2025-14273
United States13 websites



Germany26 websites
France7 websites
GB5 websites
Argentina2 websites
Netherlands2 websites
Russia2 websites
Australia1 websites
Bangladesh1 websites

Website Distribution by TLD

Number of websites using CVE-2025-14273
.com17 websites
.de14 websites
.org7 websites
.fr4 websites
.ru3 websites
.co.uk2 websites
.info2 websites
.net2 websites
.co1 websites
.edu1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14273

Top websites that are affected by CVE-2025-14273. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com Germany***,***
****.*******.com GB***,***
****.*******.com Germany*,***,***
****.**************.de Germany*,***,***
*******.org Germany*,***,***
******.***************.com United States**,***,***
*****.********.org United States**,***,***
****.***.ai United States**,***,***
**********.*******.org Germany**,***,***
****.******.fr Germany**,***,***
See full domain list

FAQ

CVE-2025-14273 is Incorrect Implementation of Authentication Algorithm in Mattermost
A total of 67 websites have been identified as vulnerable to CVE-2025-14273, based on global website indexing conducted by WebTechSurvey.
The Mattermost is affected by the CVE-2025-14273 vulnerability.
Mattermost versions up to and including 11.1 are vulnerable to CVE-2025-14273.