Atlassian Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Atlassian products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
24
In CISA KEV
13
Beyond CISA KEV
11
Sensor Observed
0
Virtual Patch Available
0
Atlassian KEVs Added by Year
24 Atlassian KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2019-8451
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network... |
Jira | High | Not in CISA | 23 Apr 2026 |
|
CVE-2019-8446
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation... |
Jira | High | Not in CISA | 30 Aug 2025 |
|
CVE-2019-8442
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0... |
Jira | High | Not in CISA | 07 Aug 2025 |
|
CVE-2022-0540
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This... |
Jira Core Server, Jira Software Server, Jira Software Data Center, Jira Service Management Server, Jira Service Management Data Center | High | Not in CISA | 17 Jun 2025 |
|
CVE-2022-39960
The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to... |
Jira | High | Not in CISA | 17 Jun 2025 |
|
CVE-2023-26255
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By... |
Jira | High | Not in CISA | 01 Jun 2025 |
|
CVE-2023-26256
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By... |
Jira | High | Not in CISA | 01 Jun 2025 |
|
CVE-2010-1165
Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka... |
JIRA | High | Not in CISA | 20 Apr 2010 |
|
CVE-2010-1164
Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or... |
JIRA | High | Not in CISA | 20 Apr 2010 |
|
CVE-2019-3396
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3... |
Confluence Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-11580
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send... |
Crowd | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-26084
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to... |
Confluence Server, Confluence Data Center | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-3398
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission... |
Confluence | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-11581
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions.... |
Jira Server and Data Center | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2021-26085
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read... |
Confluence Server, Confluence Data Center | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to... |
Confluence Data Center, Confluence Server | Confirmed | In CISA | 02 Jun 2022 |
|
CVE-2022-26138
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group... |
Questions For Confluence | Confirmed | In CISA | 29 Jul 2022 |
|
CVE-2022-36804
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from... |
Bitbucket Server, Bitbucket Data Center | Confirmed | In CISA | 30 Sep 2022 |
|
CVE-2023-22515
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown... |
Confluence Data Center, Confluence Server | Confirmed | In CISA | 05 Oct 2023 |
|
CVE-2023-22518
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows... |
Confluence Data Center, Confluence Server | Confirmed | In CISA | 07 Nov 2023 |
|
CVE-2023-22527
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an... |
Confluence Data Center, Confluence Server | Confirmed | In CISA | 24 Jan 2024 |
|
CVE-2021-26086
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in... |
Jira Server, Jira Data Center | Confirmed | In CISA | 12 Nov 2024 |
|
CVE-2024-21683
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote... |
Confluence Data Center | High | Not in CISA | 21 May 2024 |
|
CVE-2017-9506
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote... |
Atlassian OAuth Plugin | High | Not in CISA | 23 Aug 2017 |
Common Vulnerability Classes (CWE)
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 2
- CWE-863 — Incorrect Authorization 2
- CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 2
- CWE-918 — Server-Side Request Forgery (SSRF) 2
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 2
- CWE-862 — Missing Authorization 1
- CWE-88 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology