Confluence Data Center

Vendor:

First CVE: Feb 13, 2019 · Active for 7 years

37
Total CVEs
More Total CVEs than 98% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
16.2%
KEV Rate
Higher KEV Rate than 99% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Confluence Data Center over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2019
7 years ago
Most Recent CVE
Oct 21, 2025
279 days ago

CVE Severity & Scoring

Confluence Data Center37 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local3 (8.1%)
Network34 (91.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (97.3%)
High1 (2.7%)
Unknown0 (0.0%)
User Interaction
None26 (70.3%)
Unknown0 (0.0%)
Required11 (29.7%)
Privileges Required
Low16 (43.2%)
High1 (2.7%)
None20 (54.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu
Jun 3, 20229.899YESYES
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu
Aug 30, 20219.899YESYES
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using
Jan 16, 20249.898YESYES
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to re
Oct 31, 20239.898YESYES
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible C
Oct 4, 20239.898YESYES
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint.
Aug 3, 20215.397YESYES
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, wi
May 21, 20248.888NOYES
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via
Apr 1, 20214.347NOYES
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach
Dec 6, 20238.835NONO
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which f
Jul 20, 20229.834NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
6 CVEs
16.2% of CVEs· 99th percentile
Metasploit
6 CVEs
16.2% of CVEs· 98th percentile
Nuclei
8 CVEs
21.6% of CVEs· 98th percentile
ExploitDB
3 CVEs
8.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For Confluence Data Center

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.8.118.888.3%01
8.8.018.888.3%01
8.7.218.888.3%01
8.7.118.888.3%01
8.7.029.356.4%11
8.6.019.8100.0%11
7.18.039.535.7%11