Vulnerabilities > Atlassian > Jira > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-01-06 CVE-2021-43947 Unspecified vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature.
network
low complexity
atlassian
critical
9.0
2019-08-09 CVE-2019-11581 Injection vulnerability in Atlassian Jira and Jira Server
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions.
network
atlassian CWE-74
critical
9.3
2010-04-20 CVE-2010-1165 Code Injection vulnerability in Atlassian Jira
Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka attachments), (2) index (aka indexing), or (3) backup path and then uploading a file, as exploited in the wild in April 2010.
network
low complexity
atlassian CWE-94
critical
9.0