Atlassian
First CVE: Jun 14, 2017Active for: 9 years
405
CVEs Published
More CVEs Published than 85% of tracked CNAs
40.5
Avg CVEs / Year
More Avg CVEs / Year than 82% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked CNAs
3.2%
In CISA KEV
Higher KEV Rate than 94% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Atlassian as a CNA, 98.8% affect products that Atlassian develops as a vendor.
98.8%
Self-reported: 400Third-party: 5
Of all the CVEs published that affect products developed by Atlassian, 85.7% are self-published by Atlassian as a CNA.
85.7%
14.3%
Self-published: 400Published by other CNAs: 67
Trends Over Time
The number and severity of CVEs published by Atlassian over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 14, 2017
9 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by Atlassian as a CNA, regardless of affected vendor or product.
405 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36804HIGH Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21 | Aug 25, 2022 | 8.8 | 99 | YES | YES |
CVE-2022-26134CRITICAL In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu | Jun 3, 2022 | 9.8 | 99 | YES | YES |
CVE-2021-26084CRITICAL In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu | Aug 30, 2021 | 9.8 | 99 | YES | YES |
CVE-2019-3396CRITICAL The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from | Mar 25, 2019 | 9.8 | 99 | YES | YES |
CVE-2023-22527CRITICAL A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using | Jan 16, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-22518CRITICAL All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to re | Oct 31, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-22515CRITICAL Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible C | Oct 4, 2023 | 9.8 | 98 | YES | YES |
CVE-2019-11580CRITICAL Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests | Jun 3, 2019 | 9.8 | 98 | YES | YES |
CVE-2019-3398HIGH Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / | Apr 18, 2019 | 8.8 | 98 | YES | YES |
CVE-2022-26138CRITICAL The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuse | Jul 20, 2022 | 9.8 | 97 | YES | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA405 CVEs
64%
27%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local11 (2.7%)
Network393 (97.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low388 (95.8%)
High17 (4.2%)
Unknown0 (0.0%)
User Interaction
None251 (62.0%)
Unknown0 (0.0%)
Required154 (38.0%)
Privileges Required
Low153 (37.8%)
High42 (10.4%)
None210 (51.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (405 CVEs).
CISA KEV
13 CVEs
3.2% of CVEs· 94th percentile
Metasploit
11 CVEs
2.7% of CVEs· 94th percentile
Nuclei
30 CVEs
7.4% of CVEs· 94th percentile
ExploitDB
11 CVEs
2.7% of CVEs· 91st percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Atlassian as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Atlassian as a CNA — matched by CVE ID, not by organization name.