Atlassian / Confluence Server
49 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-21580 | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0,… | CRITICAL | 9.3 | Aug 18, 2026 |
| CVE-2025-22166 | This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, w… | HIGH | 8.3 | Oct 21, 2025 |
| CVE-2023-22512 | This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this v… | HIGH | 7.5 | Mar 17, 2025 |
| CVE-2024-21703 | This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. Th… | MEDIUM | 6.4 | Nov 27, 2024 |
| CVE-2024-21690 | This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4… | HIGH | 8.2 | Aug 21, 2024 |
| CVE-2024-21686 | This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Sc… | HIGH | 8.7 | Jul 16, 2024 |
| CVE-2024-21683 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Executio… | HIGH | 8.8 | May 21, 2024 |
| CVE-2024-21677 | This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Scor… | HIGH | 8.8 | Mar 19, 2024 |
| CVE-2024-21678 | This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5,… | HIGH | 8.5 | Feb 20, 2024 |
| CVE-2024-21673 | This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE… | HIGH | 8.8 | Jan 16, 2024 |
| CVE-2024-21672 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE)… | HIGH | 8.8 | Jan 16, 2024 |
| CVE-2023-22527 KEV | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected inst… | CRITICAL | 9.8 | Jan 16, 2024 |
| CVE-2024-21674 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE)… | HIGH | 7.5 | Jan 16, 2024 |
| CVE-2023-22526 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulne… | HIGH | 8.8 | Jan 16, 2024 |
| CVE-2023-22522 | This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page… | HIGH | 8.8 | Dec 6, 2023 |
| CVE-2023-22518 KEV | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthent… | CRITICAL | 9.8 | Oct 31, 2023 |
| CVE-2023-22515 KEV | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in… | CRITICAL | 9.8 | Oct 4, 2023 |
| CVE-2023-22508 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This R… | HIGH | 8.8 | Jul 18, 2023 |
| CVE-2023-22505 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This R… | HIGH | 8.8 | Jul 18, 2023 |
| CVE-2023-22504 | Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments v… | MEDIUM | 6.5 | May 25, 2023 |
| CVE-2023-22503 | Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Conf… | MEDIUM | 5.3 | May 1, 2023 |
| CVE-2020-36290 | The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 al… | MEDIUM | 5.4 | Jul 26, 2022 |
| CVE-2022-26137 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application… | HIGH | 8.8 | Jul 20, 2022 |
| CVE-2022-26136 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impa… | CRITICAL | 9.8 | Jul 20, 2022 |
| CVE-2022-26134 KEV | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbit… | CRITICAL | 9.8 | Jun 3, 2022 |
Showing 1 to 25 of 49 CVEs