Confluence
Atlassian · 19 CVEs
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration pe…
Jul 1, 2020
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.…
Feb 6, 2020
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and C…
Dec 19, 2019
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate…
Nov 8, 2019
There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An…
Aug 29, 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote a…
Apr 18, 2019
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x),…
Mar 25, 2019
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in th…
Jul 10, 2018
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML o…
Feb 2, 2018
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject…
Feb 2, 2018
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary…
Feb 2, 2018
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary…
Feb 2, 2018
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or Jav…
Dec 5, 2017
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creati…
Jun 15, 2017
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
Apr 10, 2017
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitr…
Jan 18, 2017
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName…
Apr 11, 2016
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitr…
Apr 11, 2016
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible be…
May 22, 2012
Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allo…
Dec 3, 2005
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-4027 | Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template in… | MEDIUM | 1.52% | Jul 1, 2020 |
| CVE-2019-20406 | The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local syst… | HIGH | 0.48% | Feb 6, 2020 |
| CVE-2019-15006 | There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was u… | MEDIUM | 1.91% | Dec 19, 2019 |
| CVE-2019-15005 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results… | MEDIUM | 1.33% | Nov 8, 2019 |
| CVE-2019-3394 | There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to editing a pa… | HIGH | 11.02% | Aug 29, 2019 |
| CVE-2019-3398 KEV | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attach… | HIGH | 97.03% | Apr 18, 2019 |
| CVE-2019-3395 | The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fix… | CRITICAL | 6.71% | Mar 25, 2019 |
| CVE-2018-13389 | The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attach… | MEDIUM | 1.00% | Jul 10, 2018 |
| CVE-2017-18086 | Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting… | MEDIUM | 0.81% | Feb 2, 2018 |
| CVE-2017-18085 | The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cros… | MEDIUM | 0.81% | Feb 2, 2018 |
| CVE-2017-18084 | The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scr… | MEDIUM | 0.60% | Feb 2, 2018 |
| CVE-2017-18083 | The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scr… | MEDIUM | 0.58% | Feb 2, 2018 |
| CVE-2017-16856 | The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) v… | MEDIUM | 0.81% | Dec 5, 2017 |
| CVE-2017-9505 | Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comm… | MEDIUM | 1.26% | Jun 15, 2017 |
| CVE-2016-4317 | Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. | MEDIUM | 0.71% | Apr 10, 2017 |
| CVE-2016-6283 | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileNa… | MEDIUM | 3.17% | Jan 18, 2017 |
| CVE-2015-8399 | Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecor… | MEDIUM | 60.24% | Apr 11, 2016 |
| CVE-2015-8398 | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO… | MEDIUM | 2.15% | Apr 11, 2016 |
| CVE-2012-2926 | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 be… | CRITICAL | 66.26% | May 22, 2012 |
| CVE-2005-3967 | Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary… | MEDIUM | 1.21% | Dec 3, 2005 |
Showing 1 to 19 of 19 CVEs