VYPR

Vendor CVEs

Atlassian

All CVEs

545 total · sorted by risk
  • CVE-2017-18091MedFeb 16, 2018
    risk 0.31cvss 4.8epss 0.01

    The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in…

  • CVE-2017-18084MedFeb 2, 2018
    risk 0.31cvss 4.8epss 0.01

    The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.

  • CVE-2016-4318MedApr 10, 2017
    risk 0.31cvss 4.8epss 0.01

    Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.

  • CVE-2026-77268MedSep 22, 2026
    risk 0.29cvss 5.5epss —

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processes with access through the resulting group…

  • CVE-2026-77272MedSep 22, 2026
    risk 0.28cvss 5.4epss —

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an HTML page without escaping. A crafted…

  • CVE-2025-22178MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.

  • CVE-2025-22177MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.

  • CVE-2025-22176MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.

  • CVE-2025-22174MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

  • CVE-2025-22173MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.

  • CVE-2025-22172MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.

  • CVE-2025-22171MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.

  • CVE-2025-22170MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.

  • CVE-2025-22168MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.

  • CVE-2019-15002MedFeb 11, 2025
    risk 0.28cvss 4.3epss 0.00

    An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.

  • CVE-2024-21684MedJul 24, 2024
    risk 0.28cvss 4.3epss 0.00

    There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability,…

  • CVE-2022-36800MedAug 3, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version…

  • CVE-2021-43955MedMar 16, 2022
    risk 0.28cvss 4.3epss 0.01

    The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.

  • CVE-2021-43954MedMar 14, 2022
    risk 0.28cvss 4.3epss 0.01

    The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2021-43948MedFeb 15, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.

  • CVE-2021-43953MedFeb 15, 2022
    risk 0.28cvss 4.3epss 0.00

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The…

  • CVE-2021-43950MedFeb 15, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before…

  • CVE-2021-43952MedFeb 15, 2022
    risk 0.28cvss 4.3epss 0.00

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are…

  • CVE-2021-43951MedJan 10, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before…

  • CVE-2021-43949MedJan 10, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.

  • CVE-2021-41313MedNov 1, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are…

  • CVE-2021-39124MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.

  • CVE-2021-39121MedSep 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before…

  • CVE-2020-29445MedMay 7, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.

  • CVE-2021-26075MedApr 15, 2021
    risk 0.28cvss 4.3epss 0.02

    The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data…

  • CVE-2020-29451MedFeb 15, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3,…

  • CVE-2020-36231MedFeb 2, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0…

  • CVE-2020-14192MedFeb 2, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.

  • CVE-2020-29447MedDec 21, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews. The affected versions are before version 4.7.4, and from version 4.8.0 before…

  • CVE-2020-14183MedOct 6, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before…

  • CVE-2020-14180MedSep 21, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The…

  • CVE-2020-14174MedJul 13, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from…

  • CVE-2020-14170MedJul 9, 2020
    risk 0.28cvss 4.3epss 0.01

    Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2020-4029MedJul 1, 2020
    risk 0.28cvss 4.3epss 0.01

    The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability.

  • CVE-2019-20415MedJun 30, 2020
    risk 0.28cvss 4.3epss 0.01

    Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.3, and from version 8.0.0 before 8.1.0.

  • CVE-2019-20411MedJun 29, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

  • CVE-2020-4026MedJun 3, 2020
    risk 0.28cvss 4.3epss 0.01

    The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including…

  • CVE-2020-4015MedJun 1, 2020
    risk 0.28cvss 4.3epss 0.01

    The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.

  • CVE-2020-4014MedJun 1, 2020
    risk 0.28cvss 4.3epss 0.01

    The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.

  • CVE-2019-20407MedMar 17, 2020
    risk 0.28cvss 4.3epss 0.01

    The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.

  • CVE-2019-20099MedFeb 12, 2020
    risk 0.28cvss 4.3epss 0.01

    The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the…

  • CVE-2019-20098MedFeb 12, 2020
    risk 0.28cvss 4.3epss 0.01

    The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the…

  • CVE-2019-20405MedFeb 6, 2020
    risk 0.28cvss 4.3epss 0.01

    The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.

  • CVE-2019-20404MedFeb 6, 2020
    risk 0.28cvss 4.3epss 0.01

    The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.

  • CVE-2019-20106MedFeb 6, 2020
    risk 0.28cvss 4.3epss 0.01

    Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control…

Page 10 of 11