Medium severity6.8NVD Advisory· Published Aug 14, 2019· Updated Jun 17, 2026
CVE-2019-15053
CVE-2019-15053
Description
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:atlassian:html_include_and_replace_macro:*:*:*:*:*:confluence:*:*+ 1 more
- cpe:2.3:a:atlassian:html_include_and_replace_macro:*:*:*:*:*:confluence:*:*range: >=1.1,<=1.4.2
- (no CPE)range: <1.5.0
- Confluence Server/HTML Include and replace macrodescription
- Range: <1.5.0
Patches
Vulnerability mechanics
References
1- marketplace.atlassian.com/apps/4885/html-include-and-replace-macronvdVendor Advisory
News mentions
0No linked articles in our index yet.