<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Confluence</title>
  <link>https://cvedaily.com/pages/tags/confluence.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/confluence.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Confluence</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:49 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-41103 – Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41103</guid>
    <pubDate>Tue, 12 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41103</strong></p>
  <p>Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira &amp; Confluence allows an unauthorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-21571 – This Critical severity OS Command Injection vulnerability was introduced in vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21571</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-21571</strong></p>
  <p>This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.   This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H allows an authenticated attacker to execute commands on the…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21570 – This High severity RCE (Remote Code Execution)  vulnerability was introduced in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21570</guid>
    <pubDate>Tue, 17 Mar 2026 18:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21570</strong></p>
  <p>This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.6, allows an authenticated attacker to execute malicious code on the remote system.  Atlassian recommends that Bamboo Data Center customers upgra…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27825 – MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27825</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27825</strong></p>
  <p>MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any directory boundary enforcement. An attacker who can call this tool and supply or access a Confluence attachment with malicious content can write arbitrary conte…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27826 – MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27826</guid>
    <pubDate>Tue, 10 Mar 2026 19:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27826</strong></p>
  <p>MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated attacker who can reach the mcp-atlassian HTTP endpoint can force the server process to make outbound HTTP requests to an arbitrary attacker-controlled URL by supplying two custom HTTP headers without an `Authorization` header. No authentication is requir…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13523 – Mattermost Confluence plugin version &lt;1.7.0 fails to properly escape user-contro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13523</guid>
    <pubDate>Fri, 06 Feb 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13523</strong></p>
  <p>Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermos…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21569 – This High severity XXE (XML External Entity Injection) vulnerability was introdu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21569</guid>
    <pubDate>Wed, 28 Jan 2026 01:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21569</strong></p>
  <p>This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server.  	 	This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65036 – XWiki Remote Macros provides XWiki rendering macros that are useful when migrati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65036</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65036</strong></p>
  <p>XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. This vulnerability is fixed in 1.27.1.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-65089 – XWiki Remote Macros provides XWiki rendering macros that are useful when migrati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65089</guid>
    <pubDate>Wed, 19 Nov 2025 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-65089</strong></p>
  <p>XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22166 – This High severity DoS (Denial of Service) vulnerability was introduced in versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22166</guid>
    <pubDate>Tue, 21 Oct 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22166</strong></p>
  <p>This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.  This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.  Atlassian recommends that Confluence Data Ce…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-405</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55730 – XWiki Remote Macros provides XWiki rendering macros that are useful when migrati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55730</guid>
    <pubDate>Tue, 09 Sep 2025 19:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55730</strong></p>
  <p>XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the title in the confluence paste code macro allows remote code execution for any user who can edit any page. The classes parameter is used without escaping in XWiki syntax, thus allowing XWiki syntax injection which e…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55729 – XWiki Remote Macros provides XWiki rendering macros that are useful when migrati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55729</guid>
    <pubDate>Tue, 09 Sep 2025 19:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55729</strong></p>
  <p>XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the ac:type in the ConfluenceLayoutSection macro allows remote code execution for any user who can edit any page The classes parameter is used without escaping in XWiki syntax, thus allowing XWiki syntax injection whic…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55728 – XWiki Remote Macros provides XWiki rendering macros that are useful when migrati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55728</guid>
    <pubDate>Tue, 09 Sep 2025 19:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55728</strong></p>
  <p>XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the classes parameter in the panel macro allows remote code execution for any user who can edit any page The classes parameter is used without escaping in XWiki syntax, thus allowing XWiki syntax injection which enable…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55727 – XWiki Remote Macros provides XWiki rendering macros that are useful when migrati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55727</guid>
    <pubDate>Tue, 09 Sep 2025 19:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55727</strong></p>
  <p>XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the width parameter in the column macro allows remote code execution for any user who can edit any page or who can access the CKEditor converter. The width parameter is used without escaping in XWiki syntax, thus allow…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8285 – Mattermost Confluence Plugin version &lt;1.5.0 fails to check the access of the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8285</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8285</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54525 – Mattermost Confluence Plugin version &lt;1.5.0 fails to handle unexpected request b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54525</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54525</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54478 – Mattermost Confluence Plugin version &lt;1.5.0 fails to enforce authentication of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54478</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54478</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54463 – Mattermost Confluence Plugin version &lt;1.5.0 fails to handle unexpected request b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54463</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54463</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54458 – Mattermost Confluence Plugin version &lt;1.5.0 fails to check the access of the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54458</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54458</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53910 – Mattermost Confluence Plugin version &lt;1.5.0 fails to check the access of the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53910</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53910</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-53857 – Mattermost Confluence Plugin version &lt;1.5.0 fails to check the access of the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53857</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-53857</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53514 – Mattermost Confluence Plugin version &lt;1.5.0 fails to handle unexpected request b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53514</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53514</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52931 – Mattermost Confluence Plugin version &lt;1.5.0 fails to handle unexpected request b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52931</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52931</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-49221 – Mattermost Confluence Plugin version &lt;1.5.0 fails to enforce authentication of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49221</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-49221</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48731 – Mattermost Confluence Plugin version &lt;1.5.0 fails to check the access of the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48731</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48731</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-44004 – Mattermost Confluence Plugin version &lt;1.5.0 fails to check the authorization of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44004</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-44004</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-44001 – Mattermost Confluence Plugin version &lt;1.5.0 fails to check the access of the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44001</guid>
    <pubDate>Mon, 11 Aug 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-44001</strong></p>
  <p>Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27604 – XWiki Confluence Migrator Pro helps admins to import confluence packages into th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27604</guid>
    <pubDate>Fri, 07 Mar 2025 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27604</strong></p>
  <p>XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might contain sensitive information. This vulnerability is fixed in 1.11.7.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-27603 – XWiki Confluence Migrator Pro helps admins to import confluence packages into th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27603</guid>
    <pubDate>Fri, 07 Mar 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-27603</strong></p>
  <p>XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migration Page template. This vulnerability is fixed in 1.2.0.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-53677 – File upload logic in Apache Struts is flawed. An attacker can manipulate file up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53677</guid>
    <pubDate>Wed, 11 Dec 2024 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-53677</strong></p>
  <p>File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.  This issue affects Apache Struts: from 2.0.0 before 6.4.0.  Users are recommended to upgrade to version 6.4.0 at least and migrate to the new  file upload…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21703 – This Medium severity Security Misconfiguration vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21703</guid>
    <pubDate>Wed, 27 Nov 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21703</strong></p>
  <p>This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations.    This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about the Confluence Data Center configuration which has high impact to confidentiali…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48942 – The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48942</guid>
    <pubDate>Thu, 10 Oct 2024 00:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48942</strong></p>
  <p>The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-799</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48941 – The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48941</guid>
    <pubDate>Thu, 10 Oct 2024 00:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48941</strong></p>
  <p>The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21690 – This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21690</guid>
    <pubDate>Wed, 21 Aug 2024 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21690</strong></p>
  <p>This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server.  	 	This Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability, with a CVSS Score of 7.1, allows an unauthenticated attacker to execute arbitrary HT…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21689 – This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21689</guid>
    <pubDate>Tue, 20 Aug 2024 10:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21689</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21687 – This High severity File Inclusion vulnerability was introduced in versions 9.0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21687</guid>
    <pubDate>Tue, 16 Jul 2024 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21687</strong></p>
  <p>This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server.  This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file, or execute a different files already stored locally on the server which has high…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21686 – This High severity Stored XSS vulnerability was introduced in versions 7.13 of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21686</guid>
    <pubDate>Tue, 16 Jul 2024 20:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21686</strong></p>
  <p>This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server.  This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires user interaction.  A…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23736 – Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23736</guid>
    <pubDate>Mon, 01 Jul 2024 22:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23736</strong></p>
  <p>Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21683 – This High severity RCE (Remote Code Execution) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21683</guid>
    <pubDate>Tue, 21 May 2024 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21683</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.   Atl…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23735 – Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23735</guid>
    <pubDate>Wed, 10 Apr 2024 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23735</strong></p>
  <p>Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21677 – This High severity Path Traversal vulnerability was introduced in version 6.13.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21677</guid>
    <pubDate>Tue, 19 Mar 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21677</strong></p>
  <p>This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.  Atlassian recommends that…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21682 – This High severity Injection vulnerability was introduced in Assets Discovery 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21682</guid>
    <pubDate>Tue, 20 Feb 2024 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21682</strong></p>
  <p>This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions).   Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects hardware and software that is connected to your local network and extracts detailed…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21678 – This High severity Stored XSS vulnerability was introduced in version 2.7.0 of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21678</guid>
    <pubDate>Tue, 20 Feb 2024 18:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21678</strong></p>
  <p>This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center.  This Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, low impact to integrity, no impact to availability, and requires no user interaction. Data Cen…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22512 – This High severity DoS (Denial of Service) vulnerability was introduced in versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22512</guid>
    <pubDate>Tue, 16 Jan 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22512</strong></p>
  <p>This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21674 – This High severity Remote Code Execution (RCE) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21674</guid>
    <pubDate>Tue, 16 Jan 2024 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21674</strong></p>
  <p>This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server.  Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confide…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21673 – This High severity Remote Code Execution (RCE) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21673</guid>
    <pubDate>Tue, 16 Jan 2024 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21673</strong></p>
  <p>This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server.  Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confiden…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21672 – This High severity Remote Code Execution (RCE) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21672</guid>
    <pubDate>Tue, 16 Jan 2024 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21672</strong></p>
  <p>This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server.  Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose assets in your environment susceptible to exploitation which has high impact to…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22527 – A template injection vulnerability on older versions of Confluence Data Center a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22527</guid>
    <pubDate>Tue, 16 Jan 2024 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22527</strong></p>
  <p>A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.  Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22526 – This High severity RCE (Remote Code Execution) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22526</guid>
    <pubDate>Tue, 16 Jan 2024 05:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22526</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassia…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50932 – An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50932</guid>
    <pubDate>Tue, 09 Jan 2024 07:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50932</strong></p>
  <p>An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website. If executed while an administrator is logged on to Confluence, an attacker coul…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52240 – The Kantega SAML SSO OIDC Kerberos Single Sign-on apps before 6.20.0 for Atlassi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52240</guid>
    <pubDate>Fri, 29 Dec 2023 22:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52240</strong></p>
  <p>The Kantega SAML SSO OIDC Kerberos Single Sign-on apps before 6.20.0 for Atlassian products allow XSS if SAML POST Binding is enabled. This affects 4.4.2 through 4.14.8 before 4.14.9, 5.0.0 through 5.11.4 before 5.11.5, and 6.0.0 through 6.19.0 before 6.20.0. The full product names are Kantega SAML SSO OIDC Kerberos Single Sign-on for Jira Data Center & Server (Kantega SSO Enterprise), Kantega SA…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22522 – This Template Injection vulnerability allows an authenticated attacker, includin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22522</guid>
    <pubDate>Wed, 06 Dec 2023 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22522</strong></p>
  <p>This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server versions as listed below are at risk and require immediate attention. See the a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22521 – This High severity RCE (Remote Code Execution) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22521</guid>
    <pubDate>Tue, 21 Nov 2023 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22521</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crowd Data Center and Server.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.0, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atl…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22516 – This High severity RCE (Remote Code Execution) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22516</guid>
    <pubDate>Tue, 21 Nov 2023 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22516</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22518 – All versions of Confluence Data Center and Server are affected by this unexploit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22518</guid>
    <pubDate>Tue, 31 Oct 2023 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22518</strong></p>
  <p>All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22515 – Atlassian has been made aware of an issue reported by a handful of customers whe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22515</guid>
    <pubDate>Wed, 04 Oct 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22515</strong></p>
  <p>Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.   Atlassian Cloud sites are not affected by this vulnerability. If your Confluence s…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22513 – This High severity RCE (Remote Code Execution) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22513</guid>
    <pubDate>Tue, 19 Sep 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22513</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlas…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22506 – This High severity Injection and RCE (Remote Code Execution) vulnerability known...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22506</guid>
    <pubDate>Wed, 19 Jul 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22506</strong></p>
  <p>This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center.    This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker to modify the actions taken by a system call and execute arbitrary code which has high impact to confidentiality, high im…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22508 – This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22508</guid>
    <pubDate>Tue, 18 Jul 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22508</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user inte…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22505 – This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22505</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22505</guid>
    <pubDate>Tue, 18 Jul 2023 21:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22505</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user inter…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22505">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36662 – The TechTime User Management components for Atlassian products allow stored XSS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36662</guid>
    <pubDate>Mon, 26 Jun 2023 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36662</strong></p>
  <p>The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through 2.15.24.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-33287 – A stored cross-site scripting (XSS) vulnerability in the Inline Table Editing ap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33287</guid>
    <pubDate>Wed, 31 May 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-33287</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability in the Inline Table Editing application before 3.8.0 for Confluence allows attackers to store and execute arbitrary JavaScript via a crafted payload injected into the tables.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22504 – Affected versions of Atlassian Confluence Server allow remote attackers who have...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22504</guid>
    <pubDate>Thu, 25 May 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22504</strong></p>
  <p>Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-30452 – The MoroSystems EasyMind - Mind Maps plugin before 2.15.0 for Confluence allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30452</guid>
    <pubDate>Wed, 17 May 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-30452</strong></p>
  <p>The MoroSystems EasyMind - Mind Maps plugin before 2.15.0 for Confluence allows persistent XSS when saving a Mind Map with the hyperlink parameter.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22503 – Affected versions of Atlassian Confluence Server and Data Center allow anonymous...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22503</guid>
    <pubDate>Mon, 01 May 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22503</strong></p>
  <p>Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.  This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.  The affected versions are before version 7.13.…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42978 – In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authoriza...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42978</guid>
    <pubDate>Tue, 15 Nov 2022 01:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42978</strong></p>
  <p>In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42977 – The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42977</guid>
    <pubDate>Tue, 15 Nov 2022 01:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42977</strong></p>
  <p>The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g., an SSH private key) to be downloaded.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-44724 – The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44724</guid>
    <pubDate>Fri, 04 Nov 2022 07:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-44724</strong></p>
  <p>The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-36290 – The Livesearch macro in Confluence Server and Data Center before version 7.4.5, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36290</guid>
    <pubDate>Tue, 26 Jul 2022 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-36290</strong></p>
  <p>The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26138 – The Atlassian Questions For Confluence app for Confluence Server and Data Center...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26138</guid>
    <pubDate>Wed, 20 Jul 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26138</strong></p>
  <p>The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26137 – A vulnerability in multiple Atlassian products allows a remote, unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26137</guid>
    <pubDate>Wed, 20 Jul 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26137</strong></p>
  <p>A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servl…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-180</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26136 – A vulnerability in multiple Atlassian products allows a remote, unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26136</guid>
    <pubDate>Wed, 20 Jul 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26136</strong></p>
  <p>A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, b…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-180</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26134 – In affected versions of Confluence Server and Data Center, an OGNL injection vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26134</guid>
    <pubDate>Fri, 03 Jun 2022 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26134</strong></p>
  <p>In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.1…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-1231 – XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantum...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1231</guid>
    <pubDate>Fri, 15 Apr 2022 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-1231</strong></p>
  <p>XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links i…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39114 – Affected versions of Atlassian Confluence Server and Data Center allow users wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39114</guid>
    <pubDate>Tue, 05 Apr 2022 04:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39114</strong></p>
  <p>Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43940 – Affected versions of Atlassian Confluence Server and Data Center allow authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43940</guid>
    <pubDate>Tue, 15 Feb 2022 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43940</strong></p>
  <p>Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-37412 – The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37412</guid>
    <pubDate>Wed, 15 Sep 2021 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-37412</strong></p>
  <p>The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-26084 – In affected versions of Confluence Server and Data Center, an OGNL injection vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26084</guid>
    <pubDate>Mon, 30 Aug 2021 07:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-26084</strong></p>
  <p>In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26085 – Affected versions of Atlassian Confluence Server allow remote attackers to view ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26085</guid>
    <pubDate>Tue, 03 Aug 2021 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26085</strong></p>
  <p>Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37843 – The resolution SAML SSO apps for Atlassian products allow a remote attacker to l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37843</guid>
    <pubDate>Mon, 02 Aug 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37843</strong></p>
  <p>The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6.6, 4.0.12, 5.0.5; for Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5; for Bamboo 2.5.9, 3.6.6, 4.0.12, 5.0.5; and for Fisheye 2.5.9.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-29445 – Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29445</guid>
    <pubDate>Fri, 07 May 2021 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-29445</strong></p>
  <p>Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-29444 – Affected versions of Team Calendar in Confluence Server before 7.11.0 allow atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29444</guid>
    <pubDate>Fri, 07 May 2021 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-29444</strong></p>
  <p>Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26072 – The WidgetConnector plugin in Confluence Server and Confluence Data Center befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26072</guid>
    <pubDate>Thu, 01 Apr 2021 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26072</strong></p>
  <p>The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-29448 – The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Conflue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29448</guid>
    <pubDate>Mon, 22 Feb 2021 21:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-29448</strong></p>
  <p>The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-29450 – Affected versions of Atlassian Confluence Server and Data Center allow remote at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29450</guid>
    <pubDate>Tue, 19 Jan 2021 01:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-29450</strong></p>
  <p>Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35122 – An issue was discovered in the Keysight Database Connector plugin before 1.5.0 f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35122</guid>
    <pubDate>Tue, 15 Dec 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35122</strong></p>
  <p>An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35121 – An issue was discovered in the Keysight Database Connector plugin before 1.5.0 f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35121</guid>
    <pubDate>Tue, 15 Dec 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35121</strong></p>
  <p>An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could insert arbitrary JavaScript into saved macro parameters that would execute when a user viewed a page with that instance of the macro.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24898 – The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24898</guid>
    <pubDate>Sat, 29 Aug 2020 20:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24898</strong></p>
  <p>The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24897 – The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24897</guid>
    <pubDate>Sat, 29 Aug 2020 20:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24897</strong></p>
  <p>The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the provided Markdown markup to the "Table from CSV" macro.</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14175 – Affected versions of Atlassian Confluence Server and Data Center allow remote at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14175</guid>
    <pubDate>Fri, 24 Jul 2020 07:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14175</strong></p>
  <p>Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before 7.5.2.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4027 – Affected versions of Atlassian Confluence Server and Data Center allowed remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4027</guid>
    <pubDate>Wed, 01 Jul 2020 02:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4027</strong></p>
  <p>Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version 7.4.5, and from version 7.5.0 before 7.5.1.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4020 – The file downloading functionality in the Atlassian Companion App before version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4020</guid>
    <pubDate>Mon, 01 Jun 2020 07:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4020</strong></p>
  <p>The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-20102 – The attachment-uploading feature in Atlassian Confluence Server from version 6.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20102</guid>
    <pubDate>Wed, 22 Apr 2020 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-20102</strong></p>
  <p>The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20406 – The usage of Tomcat in Confluence on the Microsoft Windows operating system befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20406</guid>
    <pubDate>Thu, 06 Feb 2020 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20406</strong></p>
  <p>The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15006 – There was a man-in-the-middle (MITM) vulnerability present in the Confluence Pre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15006</guid>
    <pubDate>Thu, 19 Dec 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15006</strong></p>
  <p>There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Previews plugin in Confluence Server and Confluence Data Center communicated with the Companion application via the atlassian-domain-for-localhost-conn…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-913</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13347 – An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13347</guid>
    <pubDate>Fri, 13 Dec 2019 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13347</strong></p>
  <p>An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by browsing the affected Jira/Confluence/Bitbucket/Bamboo instance, even when the ap…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15005 – The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15005</guid>
    <pubDate>Fri, 08 Nov 2019 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15005</strong></p>
  <p>The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bit…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3394 – There was a local file disclosure vulnerability in Confluence Server and Conflue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3394</guid>
    <pubDate>Thu, 29 Aug 2019 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3394</strong></p>
  <p>There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to editing a page is able to exploit this issue to read arbitrary file on the server under <install-directory>/confluence/WEB-INF directory, which may contain configuration files used for integrating with other services, which could potentially leak crede…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15233 – The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15233</guid>
    <pubDate>Tue, 20 Aug 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15233</strong></p>
  <p>The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15053 – The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15053</guid>
    <pubDate>Wed, 14 Aug 2019 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15053</strong></p>
  <p>The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15053">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
