Atlassian CVE Vulnerabilities & CVE List (466)

Products (CPE): — CVEs: 466

Atlassian vulnerability overview

Aggregates CVE and security vulnerability intelligence across all Atlassian-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk ssrf and vendor risk input validation and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 120 of 466 CVEs
«« First « Prev Page 1 / 24 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-21569 This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Crowd Data Center and Server customers upgrade to la [email protected] 7.9 0.02% 2026-01-28 2026-02-02
CVE-2025-22178 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22177 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22176 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22175 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist. [email protected] 5.3 0.03% 2025-10-22 2025-10-27
CVE-2025-22174 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22173 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22172 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22171 Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22170 Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22169 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22168 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist. [email protected] 5.3 0.03% 2025-10-22 2025-10-24
CVE-2025-22167 This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by the Jira JVM process. Atlassian recommends that Jira Software Data Center and Server customers upgrade to the latest version; if you are unable to do so, upgrade your instance to on [email protected] 8.7 0.05% 2025-10-22 2025-12-05
CVE-2025-22166 This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of [email protected] 8.3 0.05% 2025-10-21 2025-12-05
CVE-2025-35115 Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the contents of the download URL. Users should upgrade to Agiloft Release 30. 9119a7d8-5eab-497f-8521-727c672e3725 9.2 0.02% 2025-08-26 2025-09-02
CVE-2025-35114 Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30. 9119a7d8-5eab-497f-8521-727c672e3725 8.7 0.06% 2025-08-26 2025-09-02
CVE-2025-35113 Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Release 31. 9119a7d8-5eab-497f-8521-727c672e3725 4.8 0.26% 2025-08-26 2025-09-02
CVE-2025-35112 Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31. 9119a7d8-5eab-497f-8521-727c672e3725 5.1 0.05% 2025-08-26 2026-04-29
CVE-2025-22165 This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.  Atlassian recommends that Sourcetree for Mac users upgrade to the latest version. If you are unable to do [email protected] 5.9 0.05% 2025-07-24 2025-07-30
CVE-2025-22157 This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. Atlassian recommends that Jira Core Data Center and Server and Jira Service Management Data Center and [email protected] 7.2 0.29% 2025-05-20 2025-06-12
«« First « Prev Page 1 / 24 Next »
cvelogic Threat Intelligence