CVEs (49)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a p...Show more |
1Atlassian 1Confluence Server Jun 17, 2026 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed...Show more |
1Atlassian 2Confluence Confluence ServerJun 17, 2026 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (t...Show more |
1Atlassian 2Confluence Data Center Confluence ServerNov 21, 2024 Feb 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature. |
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource. |
1Atlassian 2Confluence Server Jira Integration For HipchatMay 13, 2026 Jan 23, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat plugin 6.26.0 before 7.8.17; and HipChat for JIRA plugin 6.26.0 before...Show more |
Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication of administrators for requests that logout the user via a comment. |
2Atlassian Gliffy3Confluence Server GliffyJiraApr 29, 2026 May 22, 2012 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or...Show more |
1Atlassian 7Bamboo ConfluenceConfluence Server+4 moreApr 29, 2026 May 22, 2012 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and...Show more |