Vulnerabilities > Atlassian > Confluence Data Center

DATE CVE VULNERABILITY TITLE RISK
2023-12-06 CVE-2023-22522 Injection vulnerability in Atlassian Confluence Server
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page.
network
low complexity
atlassian CWE-74
8.8
2023-10-31 CVE-2023-22518 Incorrect Authorization vulnerability in Atlassian Confluence Data Center
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
network
low complexity
atlassian CWE-863
critical
9.8
2023-10-04 CVE-2023-22515 Unspecified vulnerability in Atlassian Confluence Data Center and Confluence Server
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.
network
low complexity
atlassian
critical
9.8
2023-07-18 CVE-2023-22508 Unspecified vulnerability in Atlassian Confluence Data Center and Confluence Server
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server.
network
low complexity
atlassian
8.8
2023-07-18 CVE-2023-22505 Unspecified vulnerability in Atlassian Confluence Data Center and Confluence Server
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that you upgrade your instance to latest version.
network
low complexity
atlassian
8.8
2023-05-01 CVE-2023-22503 Unspecified vulnerability in Atlassian Confluence Data Center
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space.
network
low complexity
atlassian
5.3
2022-11-15 CVE-2022-42977 Path Traversal vulnerability in Atlassian Confluence Data Center
The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it.
network
low complexity
atlassian CWE-22
7.5
2022-11-15 CVE-2022-42978 Incorrect Authorization vulnerability in Atlassian Confluence Data Center
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled.
network
low complexity
atlassian CWE-863
7.5
2022-07-26 CVE-2020-36290 Cross-site Scripting vulnerability in Atlassian Confluence Data Center and Confluence Server
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.
network
low complexity
atlassian CWE-79
5.4
2022-07-20 CVE-2022-26136 Improper Authentication vulnerability in Atlassian products
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps.
network
low complexity
atlassian CWE-287
critical
9.8