About “Jira Software”

A curated feed of “Jira Software”-related CVEs appears below. We currently track 5 CVEs for this tag (all time). In the last 365 days, 1 were published. Average CVSS is 5.4 (all time; 6.5 over 365d), and 20% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').

In our taxonomy this topic maps to a LOW impact class. Atlassian apps hold code and project data. Patch, enforce SSO or MFA, restrict anonymous access, and audit marketplace apps and macros. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

Support & lifecycle: jira-software

This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.

CycleReleaseLatestEOLLTS
11.311.3.6LTS
11.211.2.1
11.111.1.1
11.011.0.1
10.710.7.4
10.610.6.1
10.510.5.1
10.410.4.1
10.310.3.22LTS
10.210.2.1 Soon
10.110.1.2 Soon
10.010.0.1 Soon
9.179.17.5 Soon
9.169.16.1 Expired
9.159.15.2 Expired
9.149.14.1 Expired
9.139.13.1 Expired
9.129.12.35 ExpiredLTS
9.119.11.3 Expired
9.109.10.2 Expired
9.99.9.2 Expired
9.89.8.2 Expired
9.79.7.2 Expired
9.69.6.0 Expired
9.59.5.1 Expired
9.49.4.30 ExpiredLTS
9.39.3.3 Expired
9.29.2.1 Expired
9.19.1.1 Expired
9.09.0.0 Expired
8.228.22.6 Expired
8.218.21.1 Expired
8.208.20.30 ExpiredLTS
8.198.19.1 Expired
8.188.18.2 Expired
8.178.17.1 Expired
8.168.16.2 Expired
8.158.15.1 Expired
8.148.14.1 Expired
8.138.13.27 ExpiredLTS
8.128.12.3 Expired
8.118.11.1 Expired
8.108.10.1 Expired
8.98.9.1 Expired
8.88.8.1 Expired
8.78.7.1 Expired
8.68.6.1 Expired
8.58.5.19 ExpiredLTS
8.48.4.3 Expired
8.38.3.5 Expired
8.28.2.6 Expired
8.18.1.3 Expired
8.08.0.3 Expired
7.137.13.18 ExpiredLTS
7.127.12.3 Expired
7.117.11.2 Expired
7.107.10.2 Expired
7.97.9.2 Expired
7.87.8.4 Expired
7.77.7.4 Expired
7.67.6.17 ExpiredLTS
7.57.5.4 Expired
7.47.4.6 Expired
7.37.3.9 Expired
7.27.2.15 Expired
7.17.1.10 Expired
7.07.0.11 Expired
6.46.4.14 Expired
6.36.3.15 Expired
6.26.2.7 Expired
6.16.1.9 Expired
6.06.0.8 Expired
5.25.2.11- Expired
5.15.1.8- Expired
5.05.0.7 Expired
4.44.4.5 Expired
4.34.3.4 Expired
4.24.2.4 Expired
4.14.1.2 Expired
4.04.0.2 Expired
3.133.13.5 Expired
3.123.12.3- Expired
3.113.11.0- Expired
3.103.10.2- Expired
3.93.9.3- Expired
3.83.8.1- Expired
3.73.7.4- Expired
3.63.6.5- Expired
3.53.5.3- Expired
3.43.4.3- Expired
3.33.3.3- Expired
3.23.2.3- Expired
3.13.1.1- Expired
3.03.0.3- Expired
2.62.6.1- Expired
2.52.5.3- Expired
2.42.4.0- Expired
2.32.3.0- Expired
2.22.2.1- Expired
2.12.1.0- Expired
1.41.4.1- Expired
1.31.3.3- Expired
1.21.2.0- Expired
1.11.1.0- Expired
1.01.0.0- Expired

Maintained Soon (≤ 180 days) Expired

Subscribe lifecycle: RSS  ·  RSS (expired)  ·  ICS

Subscribe CVEs: RSS for “Jira Software”  ·  RSS (High+Critical only)

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
2025-10-22
Medium

CVE-2025-22167

This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal…

2021-07-29
Critical

CVE-2020-36239

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from v…

2021-04-01
Low

CVE-2021-26071

The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymo…

2020-03-17
Medium

CVE-2019-20407

The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they…

2016-01-08
Low

CVE-2015-8481

Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup r…

CVE Daily Lookup — auto-links CVE IDs on any page you visit. GitHub, Jira, Confluence & more. Free.