Vulnerabilities > Atlassian > Confluence Data Center > 7.12.1

DATE CVE VULNERABILITY TITLE RISK
2023-12-06 CVE-2023-22522 Injection vulnerability in Atlassian Confluence Server
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page.
network
low complexity
atlassian CWE-74
8.8
2023-10-31 CVE-2023-22518 Incorrect Authorization vulnerability in Atlassian Confluence Data Center
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
network
low complexity
atlassian CWE-863
critical
9.8
2023-07-18 CVE-2023-22508 Unspecified vulnerability in Atlassian Confluence Data Center and Confluence Server
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server.
network
low complexity
atlassian
8.8
2023-05-01 CVE-2023-22503 Unspecified vulnerability in Atlassian Confluence Data Center
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space.
network
low complexity
atlassian
5.3
2022-04-05 CVE-2021-39114 Code Injection vulnerability in Atlassian Confluence Data Center and Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload.
network
low complexity
atlassian CWE-94
6.5
2022-02-15 CVE-2021-43940 Uncontrolled Search Path Element vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer.
6.9
2021-08-30 CVE-2021-26084 Expression Language Injection vulnerability in Atlassian Confluence Data Center and Confluence Server
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.
network
low complexity
atlassian CWE-917
critical
9.8
2021-08-03 CVE-2021-26085 Forced Browsing vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint.
network
low complexity
atlassian CWE-425
5.3