Confluence

Atlassian · 19 CVEs

CVE-2020-4027
MEDIUM

Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration pe…

Jul 1, 2020

CVE-2019-20406
HIGH

The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.…

Feb 6, 2020

CVE-2019-15006
MEDIUM

There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and C…

Dec 19, 2019

CVE-2019-15005
MEDIUM

The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate…

Nov 8, 2019

CVE-2019-3394
HIGH

There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An…

Aug 29, 2019

CVE-2019-3398
KEV HIGH

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote a…

Apr 18, 2019

CVE-2019-3395
CRITICAL

The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x),…

Mar 25, 2019

CVE-2018-13389
MEDIUM

The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in th…

Jul 10, 2018

CVE-2017-18086
MEDIUM

Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML o…

Feb 2, 2018

CVE-2017-18085
MEDIUM

The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject…

Feb 2, 2018

CVE-2017-18084
MEDIUM

The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary…

Feb 2, 2018

CVE-2017-18083
MEDIUM

The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary…

Feb 2, 2018

CVE-2017-16856
MEDIUM

The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or Jav…

Dec 5, 2017

CVE-2017-9505
MEDIUM

Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creati…

Jun 15, 2017

CVE-2016-4317
MEDIUM

Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.

Apr 10, 2017

CVE-2016-6283
MEDIUM

Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitr…

Jan 18, 2017

CVE-2015-8399
MEDIUM

Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName…

Apr 11, 2016

CVE-2015-8398
MEDIUM

Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitr…

Apr 11, 2016

CVE-2012-2926
CRITICAL

Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible be…

May 22, 2012

CVE-2005-3967
MEDIUM

Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allo…

Dec 3, 2005

Showing 1 to 19 of 19 CVEs