Atlassian

First CVE: Jun 14, 2017Active for: 9 years
405
CVEs Published
More CVEs Published than 85% of tracked CNAs
40.5
Avg CVEs / Year
More Avg CVEs / Year than 82% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked CNAs
3.2%
In CISA KEV
Higher KEV Rate than 94% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Atlassian as a CNA, 98.8% affect products that Atlassian develops as a vendor.

98.8%
Self-reported: 400Third-party: 5

Of all the CVEs published that affect products developed by Atlassian, 85.7% are self-published by Atlassian as a CNA.

85.7%
14.3%
Self-published: 400Published by other CNAs: 67

Trends Over Time

The number and severity of CVEs published by Atlassian over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 14, 2017
9 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Atlassian as a CNA, regardless of affected vendor or product.

405 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21
Aug 25, 20228.899YESYES
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu
Jun 3, 20229.899YESYES
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu
Aug 30, 20219.899YESYES
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from
Mar 25, 20199.899YESYES
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using
Jan 16, 20249.898YESYES
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to re
Oct 31, 20239.898YESYES
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible C
Oct 4, 20239.898YESYES
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests
Jun 3, 20199.898YESYES
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and /
Apr 18, 20198.898YESYES
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuse
Jul 20, 20229.897YESYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA405 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local11 (2.7%)
Network393 (97.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low388 (95.8%)
High17 (4.2%)
Unknown0 (0.0%)
User Interaction
None251 (62.0%)
Unknown0 (0.0%)
Required154 (38.0%)
Privileges Required
Low153 (37.8%)
High42 (10.4%)
None210 (51.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (405 CVEs).

CISA KEV
13 CVEs
3.2% of CVEs· 94th percentile
Metasploit
11 CVEs
2.7% of CVEs· 94th percentile
Nuclei
30 CVEs
7.4% of CVEs· 94th percentile
ExploitDB
11 CVEs
2.7% of CVEs· 91st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Atlassian as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Atlassian as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs