CVEs (36)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accept...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Jul 26, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog...Show more |
1Atlassian 11Bamboo BitbucketConfluence Data Center+8 moreJun 17, 2026 Jul 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and...Show more |
1Atlassian 11Bamboo BitbucketConfluence Data Center+8 moreJun 17, 2026 Jul 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Jun 3, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Apr 5, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Feb 15, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Aug 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Aug 3, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 May 7, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters. |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Apr 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SS...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Feb 22, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to re...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected vers...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Jul 24, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected version...Show more |
1Atlassian 8Application Links Confluence Data CenterConfluence Server+5 moreNov 21, 2024 Apr 30, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrar...Show more |
1Atlassian 2Confluence Data Center Confluence ServerNov 21, 2024 Feb 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature. |