VYPR

Vendor CVEs

Atlassian

All CVEs

507 total · sorted by risk
  • CVE-2019-20102MedApr 22, 2020
    risk 0.40cvss 6.1epss 0.01

    The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType`…

  • CVE-2020-9344MedMar 20, 2020
    risk 0.40cvss 6.1epss 0.05

    Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.

  • CVE-2019-19748MedDec 12, 2019
    risk 0.40cvss 6.1epss 0.01

    The Work Time Calendar app before 4.7.1 for Jira allows XSS.

  • CVE-2019-15008MedDec 11, 2019
    risk 0.40cvss 6.1epss 0.01

    The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.

  • CVE-2019-14996MedSep 11, 2019
    risk 0.40cvss 6.1epss 0.01

    The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

  • CVE-2019-11589MedAug 23, 2019
    risk 0.40cvss 6.1epss 0.01

    The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via…

  • CVE-2019-11585MedAug 23, 2019
    risk 0.40cvss 6.1epss 0.01

    The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open…

  • CVE-2019-11584MedAug 23, 2019
    risk 0.40cvss 6.1epss 0.01

    The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.

  • CVE-2019-3402MedMay 22, 2019
    risk 0.40cvss 6.1epss 0.09

    The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

  • CVE-2019-3400MedMay 3, 2019
    risk 0.40cvss 6.1epss 0.01

    The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter.

  • CVE-2017-18109MedMar 29, 2019
    risk 0.40cvss 6.1epss 0.01

    The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

  • CVE-2018-19498MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.02

    The Simplenia Pages plugin 2.6.0 for Atlassian Bitbucket Server has XSS.

  • CVE-2018-13402MedOct 23, 2018
    risk 0.40cvss 6.1epss 0.01

    Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version…

  • CVE-2018-13401MedOct 23, 2018
    risk 0.40cvss 6.1epss 0.01

    The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3,…

  • CVE-2018-13395MedAug 28, 2018
    risk 0.40cvss 6.1epss 0.01

    Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to…

  • CVE-2018-13392MedAug 13, 2018
    risk 0.40cvss 6.1epss 0.02

    Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.

  • CVE-2018-13390MedAug 10, 2018
    risk 0.40cvss 6.1epss 0.00

    Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.

  • CVE-2018-5232MedJul 18, 2018
    risk 0.40cvss 6.1epss 0.01

    The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.

  • CVE-2018-13387MedJul 16, 2018
    risk 0.40cvss 6.1epss 0.01

    The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7.10.0 before version 7.10.2 allows remote attackers to…

  • CVE-2017-16860MedMay 14, 2018
    risk 0.40cvss 6.1epss 0.01

    The invalidRedirectUrl template in Atlassian Application Links before version 5.2.7, from version 5.3.0 before version 5.3.4 and from version 5.4.0 before version 5.4.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability…

  • CVE-2018-5228MedApr 24, 2018
    risk 0.40cvss 6.1epss 0.01

    The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.

  • CVE-2017-18100MedApr 10, 2018
    risk 0.40cvss 6.1epss 0.01

    The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.

  • CVE-2017-18098MedApr 6, 2018
    risk 0.40cvss 6.1epss 0.01

    The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields.

  • CVE-2017-18090MedFeb 16, 2018
    risk 0.40cvss 6.1epss 0.01

    Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author.

  • CVE-2017-18086MedFeb 2, 2018
    risk 0.40cvss 6.1epss 0.01

    Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.

  • CVE-2017-18085MedFeb 2, 2018
    risk 0.40cvss 6.1epss 0.01

    The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.

  • CVE-2017-18081MedFeb 2, 2018
    risk 0.40cvss 6.1epss 0.01

    The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie.

  • CVE-2017-18039MedFeb 2, 2018
    risk 0.40cvss 6.1epss 0.01

    The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter.

  • CVE-2017-16863MedJan 18, 2018
    risk 0.40cvss 6.1epss 0.01

    The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.

  • CVE-2017-16864MedJan 12, 2018
    risk 0.40cvss 6.1epss 0.01

    The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.

  • CVE-2017-14594MedJan 12, 2018
    risk 0.40cvss 6.1epss 0.01

    The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.

  • CVE-2017-16856MedDec 5, 2017
    risk 0.40cvss 6.1epss 0.01

    The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.

  • CVE-2017-14588MedOct 11, 2017
    risk 0.40cvss 6.1epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.

  • CVE-2016-6285MedJan 31, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

  • CVE-2019-3403MedMay 22, 2019
    risk 0.39cvss 5.3epss 0.53

    The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

  • CVE-2025-35113MedAug 26, 2025
    risk 0.38cvss 5.9epss 0.00

    Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Release 31.

  • CVE-2020-14168MedJul 1, 2020
    risk 0.38cvss 5.9epss 0.02

    The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to access outgoing emails between a Jira instance and the SMTP server via man-in-the-middle (MITM)…

  • CVE-2012-1500MedFeb 13, 2020
    risk 0.38cvss 5.4epss 0.01

    Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.

  • CVE-2017-18104MedJul 24, 2018
    risk 0.38cvss 5.9epss 0.02

    The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are…

  • CVE-2017-8058MedMay 5, 2017
    risk 0.38cvss 5.9epss 0.01

    Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.

  • CVE-2022-39960MedSep 17, 2022
    risk 0.37cvss 5.3epss 0.26

    The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/…

  • CVE-2021-43959MedJul 26, 2022
    risk 0.37cvss 5.7epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running…

  • CVE-2021-39116MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the GIF Image Reader component. The affected versions are before version 8.13.14, and from version 8.14.0…

  • CVE-2020-29453MedFeb 22, 2021
    risk 0.36cvss 5.3epss 0.23

    The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an…

  • CVE-2019-8446MedAug 23, 2019
    risk 0.36cvss 5.3epss 0.18

    The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.

  • CVE-2015-8399MedApr 11, 2016
    risk 0.36cvss 4.3epss 0.61

    Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.

  • CVE-2025-57681MedJan 21, 2026
    risk 0.35cvss 5.4epss 0.00

    The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-jira9 allows users and attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. The vulnerability is exploited via a…

  • CVE-2025-67282MedJan 9, 2026
    risk 0.35cvss 5.4epss 0.00

    In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and…

  • CVE-2025-22175MedOct 22, 2025
    risk 0.35cvss 5.4epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.

  • CVE-2025-22169MedOct 22, 2025
    risk 0.35cvss 5.4epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.

Page 6 of 11