Atlassian Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Atlassian products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

24

In CISA KEV

13

Beyond CISA KEV

11

Sensor Observed

0

Virtual Patch Available

0

Atlassian KEVs Added by Year

Loading...

24 Atlassian KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2019-8451

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network...

High Not in CISA 23 Apr 2026
CVE-2019-8446

The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation...

High Not in CISA 30 Aug 2025
CVE-2019-8442

The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0...

High Not in CISA 07 Aug 2025
CVE-2022-0540

A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This...

High Not in CISA 17 Jun 2025
CVE-2022-39960

The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to...

High Not in CISA 17 Jun 2025
CVE-2023-26255

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By...

High Not in CISA 01 Jun 2025
CVE-2023-26256

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By...

High Not in CISA 01 Jun 2025
CVE-2010-1165

Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka...

High Not in CISA 20 Apr 2010
CVE-2010-1164

Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or...

High Not in CISA 20 Apr 2010
CVE-2019-3396

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3...

Confirmed In CISA 03 Nov 2021
CVE-2019-11580

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send...

Confirmed In CISA 03 Nov 2021
CVE-2021-26084

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to...

Confirmed In CISA 03 Nov 2021
CVE-2019-3398

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission...

Confirmed In CISA 03 Nov 2021
CVE-2019-11581

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions....

Confirmed In CISA 07 Mar 2022
CVE-2021-26085

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read...

Confirmed In CISA 28 Mar 2022
CVE-2022-26134

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to...

Confirmed In CISA 02 Jun 2022
CVE-2022-26138

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group...

Confirmed In CISA 29 Jul 2022
CVE-2022-36804

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from...

Confirmed In CISA 30 Sep 2022
CVE-2023-22515

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown...

Confirmed In CISA 05 Oct 2023
CVE-2023-22518

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows...

Confirmed In CISA 07 Nov 2023
CVE-2023-22527

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an...

Confirmed In CISA 24 Jan 2024
CVE-2021-26086

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in...

Confirmed In CISA 12 Nov 2024
CVE-2024-21683

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote...

High Not in CISA 21 May 2024
CVE-2017-9506

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote...

High Not in CISA 23 Aug 2017

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 2
  • CWE-863 — Incorrect Authorization 2
  • CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 2
  • CWE-918 — Server-Side Request Forgery (SSRF) 2
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 2
  • CWE-862 — Missing Authorization 1
  • CWE-88 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology