Skip to main content

Vendor/product archive

atlassian / confluence CVEs

Beta · best-effort

19 CVEs tagged to atlassian / confluence2 Critical, 2 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2018-13389

Published Jul 10, 2018

The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a co…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18086

Published Feb 2, 2018

Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18085

Published Feb 2, 2018

The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XS…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18084

Published Feb 2, 2018

The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnera…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18083

Published Feb 2, 2018

The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnera…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16856

Published Dec 5, 2017

The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in va…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9505

Published Jun 15, 2017

Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker wh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6283

Published Jan 18, 2017

Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to page…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8399

Published Apr 11, 2016

Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8398

Published Apr 11, 2016

Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3967

Published Dec 3, 2005

Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1