Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
atlassian confluence vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2016-6283
Cross-site scripting (XSS) vulnerability in Atlassian Confluence prior to 5.10.6 allows remote malicious users to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
Atlassian Confluence
1 EDB exploit
6.1
CVSSv3
CVE-2017-16856
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote malicious users to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.
Atlassian Confluence
4.3
CVSSv3
CVE-2017-9505
Atlassian Confluence starting with 4.3.0 prior to 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comment...
Atlassian Confluence
4.7
CVSSv3
CVE-2018-13389
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote malicious users to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.
Atlassian Confluence
6.1
CVSSv3
CVE-2015-8398
Cross-site scripting (XSS) vulnerability in Atlassian Confluence prior to 5.8.17 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
Atlassian Confluence
1 EDB exploit
5.4
CVSSv3
CVE-2017-18083
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
Atlassian Confluence
4.8
CVSSv3
CVE-2017-18084
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.
Atlassian Confluence
6.1
CVSSv3
CVE-2017-18085
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
Atlassian Confluence
6.1
CVSSv3
CVE-2017-18086
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.
Atlassian Confluence
4.3
CVSSv3
CVE-2020-29445
Affected versions of Confluence Server prior to 7.4.8, and versions from 7.5.0 prior to 7.11.0 allow malicious users to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.
Atlassian Confluence Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5834
CVE-2024-30100
CVE-2024-4577
physical
dos
CVE-2024-30099
CVE-2024-27801
CVE-2024-32146
logic flaw
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »