Vulnerabilities > Atlassian > Confluence Server > 7.5.0

DATE CVE VULNERABILITY TITLE RISK
2020-07-24 CVE-2020-14175 Cross-site Scripting vulnerability in Atlassian Confluence Data Center and Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters.
network
atlassian CWE-79
3.5
2020-07-01 CVE-2020-4027 Injection vulnerability in Atlassian Confluence
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros.
network
low complexity
atlassian CWE-74
6.5