Vulnerabilities > Atlassian > Confluence > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-01 CVE-2020-4027 Injection vulnerability in Atlassian Confluence
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros.
network
low complexity
atlassian CWE-74
4.7
2019-12-19 CVE-2019-15006 Improper Control of Dynamically-Managed Code Resources vulnerability in Atlassian Confluence and Confluence Server
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center.
network
high complexity
atlassian CWE-913
6.5
2019-11-08 CVE-2019-15005 Missing Authorization vulnerability in Atlassian products
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check.
network
low complexity
atlassian CWE-862
4.3
2018-07-10 CVE-2018-13389 Improper Input Validation vulnerability in Atlassian Confluence
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.
network
low complexity
atlassian CWE-20
4.7
2018-02-02 CVE-2017-18086 Cross-site Scripting vulnerability in Atlassian Confluence
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.
network
low complexity
atlassian CWE-79
6.1
2018-02-02 CVE-2017-18085 Cross-site Scripting vulnerability in Atlassian Confluence
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
network
low complexity
atlassian CWE-79
6.1
2018-02-02 CVE-2017-18084 Cross-site Scripting vulnerability in Atlassian Confluence
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.
network
low complexity
atlassian CWE-79
4.8
2018-02-02 CVE-2017-18083 Cross-site Scripting vulnerability in Atlassian Confluence
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
network
low complexity
atlassian CWE-79
5.4
2017-12-05 CVE-2017-16856 Cross-site Scripting vulnerability in Atlassian Confluence
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.
network
low complexity
atlassian CWE-79
6.1
2017-06-15 CVE-2017-9505 Incorrect Default Permissions vulnerability in Atlassian Confluence
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments.
network
low complexity
atlassian CWE-276
4.3