Vulnerabilities > Atlassian > Confluence > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-04-18 CVE-2019-3398 Path Traversal vulnerability in Atlassian Confluence
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.
network
low complexity
atlassian CWE-22
critical
9.0
2019-03-25 CVE-2019-3396 Path Traversal vulnerability in Atlassian Confluence
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
network
low complexity
atlassian CWE-22
critical
10.0