VYPR

Vendor CVEs

Atlassian

All CVEs

544 total · sorted by risk
  • CVE-2016-10716MedMar 16, 2018
    risk 0.35cvss 5.4epss 0.01

    The Mail.ru Calendar plugin before 2.5.0.61 for Atlassian Jira has XSS via the Name field in a Create Calender action, related to a MailRuCalendar.jspa#period/month URI.

  • CVE-2016-10715MedMar 16, 2018
    risk 0.35cvss 5.4epss 0.01

    The Artezio Kanban Board plugin 1.4 revision 1914 for Atlassian Jira has XSS via the Board Name in a Create New Board action, related to an artezioboard/mainPage.jspa?kanbanId=7#/kanban-view URI.

  • CVE-2017-18095MedFeb 19, 2018
    risk 0.35cvss 5.3epss 0.01

    The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.

  • CVE-2017-18092MedFeb 19, 2018
    risk 0.35cvss 5.4epss 0.01

    The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of a comment on the snippet.

  • CVE-2017-18089MedFeb 16, 2018
    risk 0.35cvss 5.4epss 0.01

    The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.

  • CVE-2017-18083MedFeb 2, 2018
    risk 0.35cvss 5.4epss 0.01

    The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.

  • CVE-2017-18082MedFeb 2, 2018
    risk 0.35cvss 5.4epss 0.01

    The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.

  • CVE-2017-18041MedFeb 2, 2018
    risk 0.35cvss 5.4epss 0.01

    The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.

  • CVE-2017-18040MedFeb 2, 2018
    risk 0.35cvss 5.4epss 0.01

    The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.

  • CVE-2017-18038MedFeb 2, 2018
    risk 0.35cvss 5.3epss 0.01

    The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the default branch name.

  • CVE-2017-18034MedFeb 2, 2018
    risk 0.35cvss 5.4epss 0.01

    The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in via a specially…

  • CVE-2017-9513MedJan 29, 2018
    risk 0.35cvss 5.4epss 0.01

    Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have…

  • CVE-2017-16865MedJan 17, 2018
    risk 0.35cvss 5.3epss 0.01

    The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource…

  • CVE-2017-14587MedOct 11, 2017
    risk 0.35cvss 5.4epss 0.01

    The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.

  • CVE-2017-9510MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.

  • CVE-2017-9509MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.

  • CVE-2017-9508MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.

  • CVE-2017-9507MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.

  • CVE-2016-4317MedApr 10, 2017
    risk 0.35cvss 5.4epss 0.01

    Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.

  • CVE-2022-38367MedSep 5, 2022
    risk 0.34cvss 5.3epss 0.01

    The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.

  • CVE-2020-14166MedJul 1, 2020
    risk 0.34cvss 4.8epss 0.02

    The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a…

  • CVE-2026-77250MedSep 22, 2026
    risk 0.33cvss 6.1epss 0.00

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directory using process-default permissions. On…

  • CVE-2020-36232MedFeb 22, 2021
    risk 0.33cvss 5.0epss 0.01

    The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary…

  • CVE-2022-36802MedOct 14, 2022
    risk 0.32cvss 4.9epss 0.01

    The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin…

  • CVE-2019-20105MedMar 17, 2020
    risk 0.32cvss 4.9epss 0.01

    The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote…

  • CVE-2019-20402MedFeb 6, 2020
    risk 0.32cvss 4.9epss 0.01

    Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.

  • CVE-2016-10740MedJan 29, 2019
    risk 0.32cvss 4.9epss 0.01

    Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources.

  • CVE-2026-77265MedSep 22, 2026
    risk 0.31cvss 5.9epss 0.00

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connection. An unauthenticated…

  • CVE-2021-43945MedFeb 28, 2022
    risk 0.31cvss 4.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The…

  • CVE-2021-43943MedFeb 24, 2022
    risk 0.31cvss 4.8epss 0.00

    Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of…

  • CVE-2021-39117MedAug 30, 2021
    risk 0.31cvss 4.8epss 0.01

    The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field.

  • CVE-2021-39112MedAug 25, 2021
    risk 0.31cvss 4.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from…

  • CVE-2021-26072MedApr 1, 2021
    risk 0.31cvss 4.3epss 0.39

    The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2020-36234MedFeb 15, 2021
    risk 0.31cvss 4.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3,…

  • CVE-2019-20900MedJul 13, 2020
    risk 0.31cvss 4.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are before version 8.7.0.

  • CVE-2020-4027MedJul 1, 2020
    risk 0.31cvss 4.7epss 0.02

    Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version…

  • CVE-2020-4025MedJul 1, 2020
    risk 0.31cvss 4.8epss 0.01

    The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or…

  • CVE-2019-20416MedJun 30, 2020
    risk 0.31cvss 4.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.

  • CVE-2019-20100MedFeb 12, 2020
    risk 0.31cvss 4.7epss 0.01

    The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version…

  • CVE-2019-15007MedDec 11, 2019
    risk 0.31cvss 4.8epss 0.01

    The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.

  • CVE-2019-8450MedSep 11, 2019
    risk 0.31cvss 4.8epss 0.01

    Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the…

  • CVE-2018-20240MedFeb 20, 2019
    risk 0.31cvss 4.8epss 0.01

    The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.

  • CVE-2018-13400MedOct 23, 2018
    risk 0.31cvss 4.7epss 0.01

    Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version…

  • CVE-2017-18103MedJul 18, 2018
    risk 0.31cvss 4.7epss 0.01

    The atlassian-http library, as used in various Atlassian products, before version 2.0.2 allows remote attackers to spoof web content in the Mozilla Firefox Browser through uploaded files that have a content-type of application/mathml+xml.

  • CVE-2018-13389MedJul 10, 2018
    risk 0.31cvss 4.7epss 0.01

    The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.

  • CVE-2018-5227MedApr 10, 2018
    risk 0.31cvss 4.8epss 0.01

    Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured…

  • CVE-2017-18094MedMar 22, 2018
    risk 0.31cvss 4.8epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the base path…

  • CVE-2015-6569MedFeb 21, 2018
    risk 0.31cvss 5.9epss 0.02

    Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a state manipulation attack.

  • CVE-2017-18093MedFeb 19, 2018
    risk 0.31cvss 4.8epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability…

  • CVE-2017-18091MedFeb 16, 2018
    risk 0.31cvss 4.8epss 0.01

    The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in…