VYPR

Confluence

by Atlassian

CVEs (72)

  • CVE-2017-18083MedFeb 2, 2018
    risk 0.35cvss 5.4epss 0.01

    The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.

  • CVE-2016-4317MedApr 10, 2017
    risk 0.35cvss 5.4epss 0.01

    Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.

  • CVE-2021-26072MedApr 1, 2021
    risk 0.31cvss 4.3epss 0.39

    The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2020-4027MedJul 1, 2020
    risk 0.31cvss 4.7epss 0.02

    Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version…

  • CVE-2018-13389MedJul 10, 2018
    risk 0.31cvss 4.7epss 0.01

    The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.

  • CVE-2017-18084MedFeb 2, 2018
    risk 0.31cvss 4.8epss 0.01

    The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.

  • CVE-2020-29445MedMay 7, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.

  • CVE-2019-15005MedNov 8, 2019
    risk 0.28cvss 4.3epss 0.01

    The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration…

  • CVE-2017-9505MedJun 15, 2017
    risk 0.28cvss 4.3epss 0.01

    Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of…

  • CVE-2012-6342May 13, 2014
    risk 0.00cvss epss 0.02

    Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication of administrators for requests that logout the user via a comment.

  • CVE-2012-2928May 22, 2012
    risk 0.00cvss epss 0.03

    The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via…

  • CVE-2005-3967Dec 3, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.queryString search module parameter.

Page 4 of 4