Atlassian
Atlassian Confluence Server: vulnerabilidades y CVE
Atlassian Confluence Server tiene 50 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 10 son críticas y 8 figuran en el catálogo de explotación activa de CISA.
CVE50
Últimos 12 meses2
Críticas10
Explotadas activamente8
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-22527 | Crítica (9.8) | 100% | ⚠ Explotación activa | 16 ene 2024 | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take… |
| CVE-2023-22518 | Crítica (9.8) | 100% | ⚠ Explotación activa | 31 oct 2023 | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence… |
| CVE-2023-22515 | Crítica (9.8) | 99% | ⚠ Explotación activa | 4 oct 2023 | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server… |
| CVE-2022-26134 | Crítica (9.8) | 100% | ⚠ Explotación activa | 3 jun 2022 | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.… |
| CVE-2021-26085 | Media (5.3) | 100% | ⚠ Explotación activa | 3 ago 2021 | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before… |
| CVE-2019-3396 | Crítica (9.8) | 100% | ⚠ Explotación activa | 25 mar 2019 | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the… |
| CVE-2019-3398 | Alta (8.8) | 97% | ⚠ Explotación activa | 18 abr 2019 | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a… |
| CVE-2021-26084 | Crítica (9.8) | 100% | ⚠ Explotación activa | 30 ago 2021 | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21580 | Crítica (9.3) | 0.51% | — | 18 ago 2026 | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0,… |
| CVE-2025-22166 | Alta (8.3) | 0.51% | — | 21 oct 2025 | This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a… |
| CVE-2024-21703 | Media (6.4) | 0.20% | — | 27 nov 2024 | This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS… |
| CVE-2024-21690 | Alta (8.2) | 0.76% | — | 21 ago 2024 | This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data… |
| CVE-2024-21686 | Alta (8.7) | 0.89% | — | 16 jul 2024 | This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute… |
| CVE-2024-21683 | Alta (8.8) | 88% | — | 21 may 2024 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an… |
| CVE-2024-21677 | Alta (8.8) | 0.93% | — | 19 mar 2024 | This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an… |
| CVE-2024-21678 | Alta (8.5) | 0.47% | — | 20 feb 2024 | This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML… |
| CVE-2023-22512 | Alta (7.5) | 15% | — | 16 ene 2024 | This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a… |
| CVE-2024-21674 | Alta (7.5) | 1.8% | — | 16 ene 2024 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector… |
| CVE-2024-21673 | Alta (8.8) | 1.5% | — | 16 ene 2024 | This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector… |
| CVE-2024-21672 | Alta (8.8) | 1.4% | — | 16 ene 2024 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of… |
| CVE-2023-22527 | Crítica (9.8) | 100% | ⚠ Explotación activa | 16 ene 2024 | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take… |
| CVE-2023-22526 | Alta (8.8) | 1.6% | — | 16 ene 2024 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated… |
| CVE-2023-22522 | Alta (8.8) | 13% | — | 6 dic 2023 | This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote… |
| CVE-2023-22518 | Crítica (9.8) | 100% | ⚠ Explotación activa | 31 oct 2023 | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence… |
| CVE-2023-22515 | Crítica (9.8) | 99% | ⚠ Explotación activa | 4 oct 2023 | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server… |
| CVE-2023-22508 | Alta (8.8) | 2.2% | — | 18 jul 2023 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score… |
| CVE-2023-22505 | Alta (8.8) | 2.1% | — | 18 jul 2023 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score… |
| CVE-2023-22504 | Media (6.5) | 0.75% | — | 25 may 2023 | Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments… |
| CVE-2023-22503 | Media (5.3) | 0.79% | — | 1 may 2023 | Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure… |
| CVE-2020-36290 | Media (5.4) | 0.68% | — | 26 jul 2022 | The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog… |
| CVE-2022-26137 | Alta (8.8) | 2.3% | — | 20 jul 2022 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed… |
| CVE-2022-26136 | Crítica (9.8) | 5.4% | — | 20 jul 2022 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how… |
| CVE-2022-26134 | Crítica (9.8) | 100% | ⚠ Explotación activa | 3 jun 2022 | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.… |
| CVE-2021-39114 | Alta (8.8) | 1.7% | — | 5 abr 2022 | Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL… |
| CVE-2021-43940 | Alta (7.8) | 0.33% | — | 15 feb 2022 | Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This… |
| CVE-2021-26084 | Crítica (9.8) | 100% | ⚠ Explotación activa | 30 ago 2021 | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.… |
| CVE-2021-26085 | Media (5.3) | 100% | ⚠ Explotación activa | 3 ago 2021 | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before… |
| CVE-2020-29445 | Media (4.3) | 1.2% | — | 7 may 2021 | Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.