Vulnerabilities > Atlassian > Confluence Data Center > 8.6.1

DATE CVE VULNERABILITY TITLE RISK
2024-07-16 CVE-2024-21686 Cross-site Scripting vulnerability in Atlassian Confluence Data Center
This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html).
network
low complexity
atlassian CWE-79
8.7
2024-03-19 CVE-2024-21677 Path Traversal vulnerability in Atlassian Confluence Data Center and Confluence Server
This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center.
network
low complexity
atlassian CWE-22
8.8
2023-12-06 CVE-2023-22522 Injection vulnerability in Atlassian Confluence Server
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page.
network
low complexity
atlassian CWE-74
8.8