Confluence Server
Vendor:
First CVE: May 22, 2012 · Active for 14 years
50
Total CVEs
More Total CVEs than 98% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
18.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Confluence Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2012
14 years ago
Most Recent CVE
Oct 21, 2025
278 days ago
CVE Severity & Scoring
Confluence Server50 CVEs
36%
44%
20%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (6.0%)
Network45 (90.0%)
Unknown2 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (92.0%)
High2 (4.0%)
Unknown2 (4.0%)
User Interaction
None36 (72.0%)
Unknown2 (4.0%)
Required12 (24.0%)
Privileges Required
Low20 (40.0%)
High2 (4.0%)
None26 (52.0%)
Unknown2 (4.0%)
Top CVEs
Signals from CVEs in this product scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26134CRITICAL In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu | Jun 3, 2022 | 9.8 | 99 | YES | YES |
CVE-2021-26084CRITICAL In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu | Aug 30, 2021 | 9.8 | 99 | YES | YES |
CVE-2019-3396CRITICAL The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from | Mar 25, 2019 | 9.8 | 99 | YES | YES |
CVE-2023-22527CRITICAL A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using | Jan 16, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-22518CRITICAL All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to re | Oct 31, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-22515CRITICAL Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible C | Oct 4, 2023 | 9.8 | 98 | YES | YES |
CVE-2019-3398HIGH Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / | Apr 18, 2019 | 8.8 | 98 | YES | YES |
CVE-2022-26138CRITICAL The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuse | Jul 20, 2022 | 9.8 | 97 | YES | YES |
CVE-2021-26085MEDIUM Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. | Aug 3, 2021 | 5.3 | 97 | YES | YES |
CVE-2024-21683HIGH This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
This RCE (Remote Code Execution) vulnerability, wi | May 21, 2024 | 8.8 | 88 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (50 CVEs).
CISA KEV
9 CVEs
18.0% of CVEs· 98th percentile
Metasploit
8 CVEs
16.0% of CVEs· 97th percentile
Nuclei
11 CVEs
22.0% of CVEs· 98th percentile
ExploitDB
6 CVEs
12.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (50 CVEs).
Media Mentions
Signals from CVEs in this product scope (50 CVEs).
Top CNAs Publishing CVEs For Confluence Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.8.1 | 1 | 8.8 | 88.3% | 0 | 1 |
| 8.8.0 | 1 | 8.8 | 88.3% | 0 | 1 |
| 8.7.2 | 1 | 8.8 | 88.3% | 0 | 1 |
| 8.7.1 | 1 | 8.8 | 88.3% | 0 | 1 |
| 8.6.0 | 1 | 9.8 | 100.0% | 1 | 1 |
| 7.18.0 | 3 | 9.5 | 35.7% | 1 | 1 |
| 7.1.0 | 1 | 7.8 | 0.5% | 0 | 0 |
| 6.0.6 | 1 | 7.5 | 4.4% | 0 | 0 |
| 6.0.5 | 1 | 7.5 | 4.4% | 0 | 0 |
| 6.0.4 | 1 | 7.5 | 4.4% | 0 | 0 |
| 6.0.3 | 1 | 7.5 | 4.4% | 0 | 0 |
| 6.0.2 | 1 | 7.5 | 4.4% | 0 | 0 |
| 6.0.1 | 1 | 7.5 | 4.4% | 0 | 0 |
| 6.0.0 | 1 | 7.5 | 4.4% | 0 | 0 |
| 5.9.9 | 1 | 7.5 | 3.7% | 0 | 0 |
| 5.9.8 | 1 | 7.5 | 3.7% | 0 | 0 |
| 5.9.7 | 1 | 7.5 | 3.7% | 0 | 0 |
| 5.9.6 | 1 | 7.5 | 3.7% | 0 | 0 |
| 5.9.5 | 1 | 7.5 | 3.7% | 0 | 0 |
| 5.9.4 | 1 | 7.5 | 3.7% | 0 | 0 |