Vulnerabilities > Atlassian > Confluence Server > 6.15.3

DATE CVE VULNERABILITY TITLE RISK
2020-04-22 CVE-2019-20102 Cross-site Scripting vulnerability in Atlassian Confluence Server
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.
network
low complexity
atlassian CWE-79
6.1
2019-12-19 CVE-2019-15006 Improper Control of Dynamically-Managed Code Resources vulnerability in Atlassian Confluence and Confluence Server
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center.
network
high complexity
atlassian CWE-913
6.5
2019-08-29 CVE-2019-3394 Path Traversal vulnerability in Atlassian Confluence
There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting.
network
low complexity
atlassian CWE-22
8.8