Atlassian
Atlassian Confluence: vulnerabilidades y CVE
Atlassian Confluence tiene 22 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses3
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73496 | Alta (7.7) | 0.48% | — | 14 sept 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled… |
| CVE-2026-73498 | Alta (7.7) | 0.48% | — | 12 ago 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb")… |
| CVE-2026-12225 | Alta (8.7) | 0.48% | — | 16 jun 2026 | syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor… |
| CVE-2020-4027 | Media (4.7) | 1.5% | — | 1 jul 2020 | Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom… |
| CVE-2019-20406 | Alta (7.8) | 0.48% | — | 6 feb 2020 | The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a… |
| CVE-2019-15006 | Media (6.5) | 1.9% | — | 19 dic 2019 | There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion… |
| CVE-2019-15005 | Media (4.3) | 1.3% | — | 8 nov 2019 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing… |
| CVE-2019-3394 | Alta (8.8) | 11% | — | 29 ago 2019 | There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to editing a page is able to exploit this issue to read arbitrary file on… |
| CVE-2019-3395 | Crítica (9.8) | 6.7% | — | 25 mar 2019 | The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3… |
| CVE-2018-13389 | Media (4.7) | 1.00% | — | 10 jul 2018 | The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml. |
| CVE-2017-18086 | Media (6.1) | 0.81% | — | 2 feb 2018 | Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter. |
| CVE-2017-18085 | Media (6.1) | 0.81% | — | 2 feb 2018 | The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key… |
| CVE-2017-18084 | Media (4.8) | 0.60% | — | 2 feb 2018 | The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a… |
| CVE-2017-18083 | Media (5.4) | 0.58% | — | 2 feb 2018 | The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an… |
| CVE-2017-16856 | Media (6.1) | 0.81% | — | 5 dic 2017 | The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as… |
| CVE-2017-9505 | Media (4.3) | 1.3% | — | 15 jun 2017 | Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive… |
| CVE-2016-4317 | Media (5.4) | 0.71% | — | 10 abr 2017 | Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. |
| CVE-2016-6283 | Media (6.1) | 3.2% | — | 18 ene 2017 | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action. |
| CVE-2015-8399 | Media (4.3) | 60% | — | 11 abr 2016 | Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action. |
| CVE-2015-8398 | Media (6.1) | 2.1% | — | 11 abr 2016 | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check. |
| CVE-2012-2926 | Crítica (9.1) | 66% | — | 22 may 2012 | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and… |
| CVE-2005-3967 | Media (4.3) | 1.2% | — | 3 dic 2005 | Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.queryString search… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.