Atlassian Confluence Server vulnerabilities
51 known vulnerabilities affecting atlassian/confluence_server.
Total CVEs
51
CISA KEV
8
actively exploited
Public exploits
11
Exploited in wild
10
Severity breakdown
CRITICAL9HIGH22MEDIUM20
Vulnerabilities
Page 3 of 3
CVE-2012-6342P4MEDIUMCVSS 6.8v3.4.62014-05-13
CVE-2012-6342 [MEDIUM] CWE-352 CVE-2012-6342: Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allow
Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication of administrators for requests that logout the user via a comment.
nvd
CVE-2018-20239P4MEDIUMCVSS 5.4fixed in 6.15.22019-04-30
CVE-2018-20239 [MEDIUM] CWE-79 CVE-2018-20239: Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a pl
nvd
CVE-2023-22503P4MEDIUMCVSS 5.3fixed in 7.13.15≥ 7.14.0, < 7.19.7+2 more2023-05-01
CVE-2023-22503 [MEDIUM] CWE-200 CVE-2023-22503: Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.
This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.
Th
nvd
CVE-2020-4027P4MEDIUMCVSS 4.7≥ 7.5.0, < 7.5.1≥ unspecified, < 7.4.5+2 more2020-07-01
CVE-2020-4027 [MEDIUM] CWE-74 CVE-2020-4027: Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with syste
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version 7.4.5, and from version 7.5.0 before 7.5.1.
nvd
CVE-2019-20102P4MEDIUMCVSS 6.1≥ 6.14.0, ≤ 6.14.3≥ 6.15.0, < 6.15.5+4 more2020-04-22
CVE-2019-20102 [MEDIUM] CWE-79 CVE-2019-20102: The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.
nvd
CVE-2020-14175P4MEDIUMCVSS 5.4fixed in 7.4.2≥ 7.5.0, < 7.5.2+3 more2020-07-24
CVE-2020-14175 [MEDIUM] CWE-79 CVE-2020-14175: Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject ar
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before 7.5.2.
nvd
CVE-2020-29444P4MEDIUMCVSS 5.4fixed in 7.11.0≥ unspecified, < 7.11.02021-05-07
CVE-2020-29444 [MEDIUM] CWE-79 CVE-2020-29444: Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbi
Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.
nvd
CVE-2020-36290P4MEDIUMCVSS 5.4fixed in 7.4.5≥ 7.5.0, < 7.6.3+6 more2022-07-26
CVE-2020-36290 [MEDIUM] CWE-79 CVE-2020-36290: The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 b
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.
nvd
CVE-2019-15005P4MEDIUMCVSS 4.3≥ unspecified, < 7.0.12019-11-08
CVE-2019-15005 [MEDIUM] CWE-862 CVE-2019-15005: The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivilege
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulne
nvd
CVE-2020-29445P4MEDIUMCVSS 4.3fixed in 7.4.8≥ 7.5.0, < 7.11.0+3 more2021-05-07
CVE-2020-29445 [MEDIUM] CWE-918 CVE-2020-29445: Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow att
Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.
nvd
CVE-2017-9505P4MEDIUMCVSS 4.3vVersions of Confluence starting with 4.3.0 before 6.2.1 are affected by this vulnerability.2017-06-15
CVE-2017-9505 [MEDIUM] CWE-276 CVE-2017-9505: Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they
nvd
← Previous3 / 3