VYPR

Confluence

by Atlassian

CVEs (72)

  • CVE-2019-15053MedAug 14, 2019
    risk 0.44cvss 6.8epss 0.01

    The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.

  • CVE-2016-6283MedJan 18, 2017
    risk 0.43cvss 6.1epss 0.04

    Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.

  • CVE-2015-8398MedApr 11, 2016
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.

  • CVE-2024-21703MedNov 27, 2024
    risk 0.42cvss 6.4epss 0.00

    This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows…

  • CVE-2023-22504MedMay 25, 2023
    risk 0.42cvss 6.5epss 0.01

    Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

  • CVE-2020-29450MedJan 19, 2021
    risk 0.42cvss 6.5epss 0.02

    Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0.

  • CVE-2019-15006MedDec 19, 2019
    risk 0.42cvss 6.5epss 0.02

    There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Previews plugin in Confluence…

  • CVE-2018-20237MedFeb 13, 2019
    risk 0.42cvss 6.5epss 0.02

    Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature.

  • CVE-2021-37412MedSep 15, 2021
    risk 0.40cvss 6.1epss 0.01

    The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar.

  • CVE-2019-20102MedApr 22, 2020
    risk 0.40cvss 6.1epss 0.01

    The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType`…

  • CVE-2017-18086MedFeb 2, 2018
    risk 0.40cvss 6.1epss 0.01

    Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.

  • CVE-2017-18085MedFeb 2, 2018
    risk 0.40cvss 6.1epss 0.01

    The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.

  • CVE-2017-16856MedDec 5, 2017
    risk 0.40cvss 6.1epss 0.01

    The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.

  • CVE-2015-8399MedApr 11, 2016
    risk 0.36cvss 4.3epss 0.61

    Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.

  • CVE-2023-22503MedMay 1, 2023
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This…

  • CVE-2020-36290MedJul 26, 2022
    risk 0.35cvss 5.4epss 0.01

    The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site…

  • CVE-2020-29444MedMay 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.

  • CVE-2020-29448MedFeb 22, 2021
    risk 0.35cvss 5.3epss 0.02

    The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories…

  • CVE-2020-14175MedJul 24, 2020
    risk 0.35cvss 5.4epss 0.01

    Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before…

  • CVE-2018-20239MedApr 30, 2019
    risk 0.35cvss 5.4epss 0.03

    Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS)…