Vulnerabilities > Atlassian > Confluence Server > 7.1.2

DATE CVE VULNERABILITY TITLE RISK
2021-01-19 CVE-2020-29450 Unrestricted Upload of File with Dangerous Type vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature.
network
low complexity
atlassian CWE-434
6.5
2020-07-24 CVE-2020-14175 Cross-site Scripting vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters.
network
low complexity
atlassian CWE-79
5.4