📦 Confluence Server

by Atlassian

🔍 What is Confluence Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-22527

CRITICAL CVSS 9.8 Jan 16, 2024

This is a critical template injection vulnerability (CWE-74) in older Confluence Data Center and Server versions that allows unauthenticated attackers to execute arbitrary code remotely. Affected orga...

CVE-2023-22518

CRITICAL CVSS 9.8 Oct 31, 2023

CVE-2023-22518 is an improper authorization vulnerability in Confluence Data Center and Server that allows unauthenticated attackers to reset the application and create administrator accounts. This le...

CVE-2023-22515

CRITICAL CVSS 9.8 Oct 4, 2023

CVE-2023-22515 is a critical vulnerability in Atlassian Confluence Data Center and Server that allows unauthenticated attackers to create administrator accounts and gain full control of affected insta...

CVE-2022-26136

CRITICAL CVSS 9.8 Jul 20, 2022

This vulnerability allows remote unauthenticated attackers to bypass Servlet Filters in multiple Atlassian products, potentially leading to authentication bypass and cross-site scripting attacks. Orga...

CVE-2022-26134

CRITICAL CVSS 9.8 Jun 3, 2022

CVE-2022-26134 is a critical OGNL injection vulnerability in Atlassian Confluence Server and Data Center that allows unauthenticated attackers to execute arbitrary code remotely. This affects Confluen...

CVE-2021-26084

CRITICAL CVSS 9.8 Aug 30, 2021

CVE-2021-26084 is a critical OGNL injection vulnerability in Confluence Server and Data Center that allows unauthenticated attackers to execute arbitrary code on vulnerable instances. This affects org...

CVE-2025-22166

HIGH CVSS 7.5 Oct 21, 2025

This high-severity Denial of Service vulnerability in Confluence Data Center allows attackers to make resources unavailable to legitimate users by disrupting services. It affects Confluence Data Cente...

CVE-2024-21690

HIGH CVSS 8.2 Aug 21, 2024

This high-severity vulnerability in Confluence Data Center and Server allows unauthenticated attackers to execute reflected XSS attacks and CSRF attacks. It affects users running vulnerable versions o...

CVE-2024-21686

HIGH CVSS 8.7 Jul 16, 2024

This is a stored cross-site scripting (XSS) vulnerability in Confluence Data Center and Server that allows authenticated attackers to inject malicious HTML/JavaScript into web pages. When victims view...

CVE-2024-21683

HIGH CVSS 8.8 May 21, 2024

This is a high-severity remote code execution vulnerability in Confluence Data Center and Server that allows authenticated attackers to execute arbitrary code on affected systems. It affects Confluenc...

CVE-2024-21677

HIGH CVSS 8.8 Mar 19, 2024

This is a high-severity path traversal vulnerability (CWE-22) in Confluence Data Center and Server that allows unauthenticated attackers to access or manipulate files outside intended directories. It ...

CVE-2023-22512

HIGH CVSS 7.5 Jan 16, 2024

This is a high-severity denial-of-service vulnerability in Confluence Data Center and Server that allows unauthenticated attackers to disrupt service availability. It affects versions starting from 5....

CVE-2024-21673

HIGH CVSS 8.8 Jan 16, 2024

This is a high-severity Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server that allows authenticated attackers to execute arbitrary code on affected systems. It affects...

CVE-2023-22526

HIGH CVSS 8.8 Jan 16, 2024

This is a high-severity remote code execution vulnerability in Confluence Data Center and Server that allows authenticated attackers to execute arbitrary code on affected systems. It affects versions ...

CVE-2023-22522

HIGH CVSS 8.8 Dec 6, 2023

This is a template injection vulnerability in Confluence Data Center and Server that allows authenticated attackers (including anonymous users) to inject malicious input into pages, leading to remote ...

CVE-2023-22508

HIGH CVSS 8.8 Jul 18, 2023

CVE-2023-22508 is a high-severity remote code execution vulnerability in Confluence Data Center & Server that allows authenticated attackers to execute arbitrary code on affected systems. This affects...

CVE-2021-43940

HIGH CVSS 7.8 Feb 15, 2022

This CVE describes a DLL hijacking vulnerability in Atlassian Confluence Server and Data Center installers on Windows. Authenticated local attackers can exploit this to elevate privileges on the local...