VYPR

HTML Include And Replace Macro

by Atlassian

CVEs (1)

  • CVE-2019-15053MedAug 14, 2019
    risk 0.44cvss 6.8epss 0.01

    The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.