Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
confluence vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2017-9505
Atlassian Confluence starting with 4.3.0 prior to 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comment...
Atlassian Confluence
312
VMScore
CVE-2016-4317
Atlassian Confluence Server prior to 5.9.11 has XSS on the viewmyprofile.action page.
Atlassian Confluence
405
VMScore
CVE-2015-8399
Atlassian Confluence prior to 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.
Atlassian Confluence
1 EDB exploit
383
VMScore
CVE-2018-13389
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote malicious users to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.
Atlassian Confluence
435
VMScore
CVE-2016-6283
Cross-site scripting (XSS) vulnerability in Atlassian Confluence prior to 5.10.6 allows remote malicious users to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
Atlassian Confluence
1 EDB exploit
383
VMScore
CVE-2017-18085
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
Atlassian Confluence
312
VMScore
CVE-2017-18083
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
Atlassian Confluence
312
VMScore
CVE-2017-18084
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.
Atlassian Confluence
383
VMScore
CVE-2017-18086
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.
Atlassian Confluence
435
VMScore
CVE-2015-8398
Cross-site scripting (XSS) vulnerability in Atlassian Confluence prior to 5.8.17 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
Atlassian Confluence
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
administrator privileges
CVE-2024-1579
hardcoded
CVE-2023-20198
CVE-2024-33587
CVE-2024-33449
CVE-2024-4308
HTML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »