Atlassian / Confluence
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-4027 | Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template in… | MEDIUM | 4.7 | Jul 1, 2020 |
| CVE-2019-20406 | The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local syst… | HIGH | 7.8 | Feb 6, 2020 |
| CVE-2019-15006 | There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was u… | MEDIUM | 6.5 | Dec 19, 2019 |
| CVE-2019-15005 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results… | MEDIUM | 4.3 | Nov 8, 2019 |
| CVE-2019-3394 | There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to editing a pa… | HIGH | 8.8 | Aug 29, 2019 |
| CVE-2019-3398 KEV | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attach… | HIGH | 8.8 | Apr 18, 2019 |
| CVE-2019-3395 | The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fix… | CRITICAL | 9.8 | Mar 25, 2019 |
| CVE-2018-13389 | The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attach… | MEDIUM | 4.7 | Jul 10, 2018 |
| CVE-2017-18086 | Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting… | MEDIUM | 6.1 | Feb 2, 2018 |
| CVE-2017-18085 | The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cros… | MEDIUM | 6.1 | Feb 2, 2018 |
| CVE-2017-18084 | The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scr… | MEDIUM | 4.8 | Feb 2, 2018 |
| CVE-2017-18083 | The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scr… | MEDIUM | 5.4 | Feb 2, 2018 |
| CVE-2017-16856 | The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) v… | MEDIUM | 6.1 | Dec 5, 2017 |
| CVE-2017-9505 | Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comm… | MEDIUM | 4.3 | Jun 15, 2017 |
| CVE-2016-4317 | Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. | MEDIUM | 5.4 | Apr 10, 2017 |
| CVE-2016-6283 | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileNa… | MEDIUM | 6.1 | Jan 18, 2017 |
| CVE-2015-8399 | Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecor… | MEDIUM | 4.3 | Apr 11, 2016 |
| CVE-2015-8398 | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO… | MEDIUM | 6.1 | Apr 11, 2016 |
| CVE-2012-2926 | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 be… | CRITICAL | 9.1 | May 22, 2012 |
| CVE-2005-3967 | Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary… | MEDIUM | 4.3 | Dec 3, 2005 |
Showing 1 to 19 of 19 CVEs