VYPR

Vendor CVEs

Atlassian

All CVEs

507 total · sorted by risk
  • CVE-2020-36234MedFeb 15, 2021
    risk 0.31cvss 4.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3,…

  • CVE-2019-20900MedJul 13, 2020
    risk 0.31cvss 4.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are before version 8.7.0.

  • CVE-2020-4027MedJul 1, 2020
    risk 0.31cvss 4.7epss 0.02

    Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version…

  • CVE-2020-4025MedJul 1, 2020
    risk 0.31cvss 4.8epss 0.01

    The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or…

  • CVE-2019-20416MedJun 30, 2020
    risk 0.31cvss 4.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.

  • CVE-2019-20100MedFeb 12, 2020
    risk 0.31cvss 4.7epss 0.01

    The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version…

  • CVE-2019-15007MedDec 11, 2019
    risk 0.31cvss 4.8epss 0.01

    The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.

  • CVE-2019-8450MedSep 11, 2019
    risk 0.31cvss 4.8epss 0.01

    Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the…

  • CVE-2018-20240MedFeb 20, 2019
    risk 0.31cvss 4.8epss 0.01

    The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.

  • CVE-2018-13400MedOct 23, 2018
    risk 0.31cvss 4.7epss 0.01

    Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version…

  • CVE-2017-18103MedJul 18, 2018
    risk 0.31cvss 4.7epss 0.01

    The atlassian-http library, as used in various Atlassian products, before version 2.0.2 allows remote attackers to spoof web content in the Mozilla Firefox Browser through uploaded files that have a content-type of application/mathml+xml.

  • CVE-2018-13389MedJul 10, 2018
    risk 0.31cvss 4.7epss 0.01

    The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.

  • CVE-2018-5227MedApr 10, 2018
    risk 0.31cvss 4.8epss 0.01

    Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured…

  • CVE-2017-18094MedMar 22, 2018
    risk 0.31cvss 4.8epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the base path…

  • CVE-2017-18093MedFeb 19, 2018
    risk 0.31cvss 4.8epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability…

  • CVE-2017-18091MedFeb 16, 2018
    risk 0.31cvss 4.8epss 0.01

    The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in…

  • CVE-2017-18084MedFeb 2, 2018
    risk 0.31cvss 4.8epss 0.01

    The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.

  • CVE-2016-4318MedApr 10, 2017
    risk 0.31cvss 4.8epss 0.01

    Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.

  • CVE-2025-22178MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.

  • CVE-2025-22177MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.

  • CVE-2025-22176MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.

  • CVE-2025-22174MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

  • CVE-2025-22173MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.

  • CVE-2025-22172MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.

  • CVE-2025-22171MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.

  • CVE-2025-22170MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.

  • CVE-2025-22168MedOct 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.

  • CVE-2019-15002MedFeb 11, 2025
    risk 0.28cvss 4.3epss 0.00

    An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.

  • CVE-2024-21684MedJul 24, 2024
    risk 0.28cvss 4.3epss 0.00

    There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability,…

  • CVE-2022-36800MedAug 3, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version…

  • CVE-2021-43955MedMar 16, 2022
    risk 0.28cvss 4.3epss 0.01

    The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.

  • CVE-2021-43954MedMar 14, 2022
    risk 0.28cvss 4.3epss 0.01

    The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2021-43948MedFeb 15, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.

  • CVE-2021-43953MedFeb 15, 2022
    risk 0.28cvss 4.3epss 0.00

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The…

  • CVE-2021-43950MedFeb 15, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before…

  • CVE-2021-43952MedFeb 15, 2022
    risk 0.28cvss 4.3epss 0.00

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are…

  • CVE-2021-43951MedJan 10, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before…

  • CVE-2021-43949MedJan 10, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.

  • CVE-2021-41313MedNov 1, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are…

  • CVE-2021-39124MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.

  • CVE-2021-39121MedSep 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before…

  • CVE-2020-29445MedMay 7, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.

  • CVE-2021-26075MedApr 15, 2021
    risk 0.28cvss 4.3epss 0.02

    The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data…

  • CVE-2020-29451MedFeb 15, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3,…

  • CVE-2020-36231MedFeb 2, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0…

  • CVE-2020-14192MedFeb 2, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.

  • CVE-2020-29447MedDec 21, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews. The affected versions are before version 4.7.4, and from version 4.8.0 before…

  • CVE-2020-14183MedOct 6, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before…

  • CVE-2020-14180MedSep 21, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The…

  • CVE-2020-14174MedJul 13, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from…