Known vulnerabilities in Confluence Data Center

Vendor: Atlassian
Software CPE: cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 180
Public exploits: 26
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Confluence Data Center Confluence Data Center is affected by 180 known vulnerabilities: 2 critical, 21 high, 131 medium, 26 low Critical High Medium Low

Vulnerabilities (180)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139385 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-46625
CWE-1321 Medium
No
No
9.2.22, 10.2.14 26.07.2026 SB2026072610
SB2026072615
SB2026072616
#VU139384 - Inefficient Regular Expression Complexity
CVE-2026-33671
CWE-1333 Medium
No
No
9.2.22, 10.2.14 26.07.2026 SB2026072609
SB2026072616
SB2026081816
and 2 more
#VU138926 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-12143
CWE-93 High
No
No
9.2.22, 10.2.14 21.07.2026 SB20260721116
SB2026072414
SB2026072616
and 4 more
#VU133099 - Allocation of Resources Without Limits or Throttling
CVE-2026-44488
CWE-770 Medium
No
No
9.2.22, 10.2.14 31.05.2026 SB2026052927
SB2026061992
SB2026070157
and 8 more
#VU133098 - Insertion of Sensitive Information Into Sent Data
CVE-2026-44487
CWE-201 Low
No
No
9.2.22, 10.2.14 31.05.2026 SB2026052927
SB2026061992
SB2026070157
and 9 more
#VU133097 - Exposure of sensitive information to an unauthorized actor
CVE-2026-44486
CWE-200 Medium
No
No
9.2.22, 10.2.14 31.05.2026 SB2026052927
SB2026061992
SB2026070157
and 6 more
#VU133096 - Inefficient Regular Expression Complexity
CVE-2026-44496
CWE-1333 Medium
No
No
9.2.22, 10.2.14 31.05.2026 SB2026052927
SB2026061992
SB2026070157
and 6 more
#VU132949 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-44495
CWE-1321 Medium
No
No
9.2.22, 10.2.14 29.05.2026 SB20260424169
SB2026061999
SB20260619101
and 10 more
#VU132756 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-44490
CWE-1321 Medium
Available
No
9.2.22, 10.2.14 29.05.2026 SB2026052927
SB2026071542
SB2026072613
and 3 more
#VU132755 - Server-Side Request Forgery (SSRF)
CVE-2026-44492
CWE-918 Medium
Available
No
9.2.22, 10.2.14 29.05.2026 SB2026052927
SB2026061992
SB2026070157
and 6 more
#VU132750 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-44494
CWE-1321 High
Available
No
9.2.22, 10.2.14 29.05.2026 SB2026052927
SB2026070157
SB2026070202
and 10 more
#VU132291 - Resource exhaustion
CVE-2026-48779
CWE-400 Medium
No
No
9.2.5 25.05.2026 SB2026052550
SB2026062253
SB2026062254
and 4 more
#VU131921 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-40175
CWE-113 Medium
No
No
9.2.22, 10.2.14 20.05.2026 SB2026052045
SB2026052051
SB2026052052
and 21 more
#VU128353 - Resource exhaustion
CVE-2026-34043
CWE-400 Medium
No
No
9.2.21, 10.2.14 28.04.2026 SB20260428183
SB2026052719
SB2026052720
and 7 more
#VU127606 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-42035
CWE-113 Medium
No
No
9.2.22, 10.2.14 24.04.2026 SB20260424169
SB2026061912
SB2026061913
and 15 more
#VU127603 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42033
CWE-1321 Medium
No
No
9.2.22, 10.2.14 24.04.2026 SB20260424169
SB2026061954
SB2026061992
and 11 more
#VU127595 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42041
CWE-1321 Medium
No
No
9.2.22, 10.2.14 24.04.2026 SB20260424169
SB2026061954
SB2026062221
and 8 more
#VU127592 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42264
CWE-1321 Medium
No
No
9.2.22, 10.2.14 24.04.2026 SB20260424168
SB2026061999
SB20260619101
and 9 more
#VU125866 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-2332
CWE-444 Medium
No
No
9.2.22, 10.2.13 14.04.2026 SB2026041433
SB2026050517
SB20260507308
and 10 more
#VU116684 - Improper input validation
CVE-2025-11226
CWE-20 Medium
No
No
9.2.14, 10.2.10 07.10.2025 SB2025100745
SB2025100746
SB2025112108
and 19 more


Showing elements 1 - 20 out of 180