Known vulnerabilities in Confluence Server

Vendor: Atlassian
Software CPE: cpe:2.3:a:atlassian:atlassian_confluence_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 117
Public exploits: 16
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Confluence Server Confluence Server is affected by 117 known vulnerabilities: 2 critical, 17 high, 74 medium, 24 low Critical High Medium Low

Vulnerabilities (117)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121937 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-53689
CWE-611 Medium
No
No
9.2.11, 10.1.0 22.01.2026 SB2026012219
SB2026012277
#VU119401 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-64756
CWE-78 Medium
No
No
9.0.2, 9.2.15, 10.2.7 09.12.2025 SB2025120922
SB2025120932
SB20251210178
and 18 more
#VU117332 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-59343
CWE-22 High
No
No
8.5.10, 9.2.5, 9.3.1, 9.5.1 17.10.2025 SB2025101702
SB2025101703
SB2025101704
and 22 more
#VU115573 - Protection Mechanism Failure
CVE-2025-41249
CWE-693 Medium
No
No
9.2.14, 10.2.3 16.09.2025 SB20250916314
SB2025100741
SB20251008143
and 62 more
#VU115570 - Protection Mechanism Failure
CVE-2025-41248
CWE-693 Medium
No
No
10.1.1 16.09.2025 SB20250916313
SB2025100741
SB20251008143
and 33 more
#VU114385 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-54988
CWE-611 Medium
Available
No
8.5.31, 9.2.13, 10.2.2 22.08.2025 SB2025082219
SB2025083007
SB2025083008
and 31 more
#VU112166 - Improper Authentication
CVE-2025-49146
CWE-287 High
No
No
9.2.11 04.07.2025 SB2025070405
SB2025070406
SB2025070708
and 13 more
#VU112157 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-48387
CWE-22 High
No
No
8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2, 10.1.0 03.07.2025 SB2025070352
SB2025070353
SB2025070354
and 13 more
#VU111162 - Resource exhaustion
CVE-2025-48976
CWE-400 Medium
Available
No
9.2.7, 9.5.3 16.06.2025 SB2025061634
SB2025061635
SB2025061927
and 156 more
#VU106282 - Improper Link Resolution Before File Access ('Link Following')
CVE-2024-12905
CWE-59 High
No
No
8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2 31.03.2025 SB2025033140
SB2025033150
SB2025033151
and 15 more
#VU98132 - Inefficient Regular Expression Complexity
CVE-2024-45296
CWE-1333 Low
No
No
8.5.17, 9.2.6, 9.4.0, 9.5.1, 10.0.2, 10.1.0 08.10.2024 SB2024100822
SB2024100823
SB2024100826
and 87 more
#VU95816 - Server-Side Request Forgery (SSRF)
CVE-2024-29415
CWE-918 Medium
Available
No
8.5.20, 9.2.6, 9.3.1, 9.4.0, 9.5.2, 10.0.2 13.08.2024 SB2024081345
SB2024082612
SB2024082760
and 14 more
#VU94329 - NULL Pointer Dereference
CVE-2024-37890
CWE-476 Medium
No
No
8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2, 10.1.0 15.07.2024 SB2024071508
SB2024071933
SB2024081608
and 32 more
#VU86944 - Server-Side Request Forgery (SSRF)
CVE-2023-42282
CWE-918 Medium
No
No
8.5.18, 9.2.1, 9.3.1, 9.5.4, 10.0.2, 10.1.0 01.03.2024 SB2024030127
SB2024030148
SB2024030415
and 29 more
#VU78932 - Incorrect Regular Expression
CVE-2022-25883
CWE-185 Medium
No
No
9.2.1, 9.4.0, 9.5.1, 10.2.3 03.08.2023 SB2023080361
SB2023080362
SB2023081514
and 73 more
#VU73969 - Incorrect Regular Expression
CVE-2022-25927
CWE-185 Medium
No
No
9.2.14, 10.2.3 23.03.2023 SB2023032313
SB2023032315
SB2023032710
and 19 more
#VU70123 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-37601
CWE-94 High
No
No
9.2.1, 9.4.0, 9.5.1, 10.0.2 12.12.2022 SB2022121220
SB2023010419
SB2023011403
and 20 more
#VU70122 - Incorrect Regular Expression
CVE-2022-37599
CWE-185 Medium
No
No
9.2.1, 9.4.0, 9.5.1, 10.0.2 12.12.2022 SB2022121221
SB2023010424
SB2023020920
and 19 more
#VU70121 - Incorrect Regular Expression
CVE-2022-37603
CWE-185 Medium
No
No
9.2.1, 9.4.0, 9.5.1, 10.0.2 12.12.2022 SB2022121221
SB2022121222
SB2023010418
and 29 more
#VU52985 - Incorrect Regular Expression
CVE-2020-28469
CWE-185 Medium
No
No
9.2.13, 10.2.2 10.05.2021 SB2021051002
SB2021051004
SB2021072625
and 26 more


Showing elements 1 - 20 out of 117