Confluence Server

Vendor:

First CVE: May 22, 2012 · Active for 14 years

50
Total CVEs
More Total CVEs than 98% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
18.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Confluence Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2012
14 years ago
Most Recent CVE
Oct 21, 2025
278 days ago

CVE Severity & Scoring

Confluence Server50 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local3 (6.0%)
Network45 (90.0%)
Unknown2 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (92.0%)
High2 (4.0%)
Unknown2 (4.0%)
User Interaction
None36 (72.0%)
Unknown2 (4.0%)
Required12 (24.0%)
Privileges Required
Low20 (40.0%)
High2 (4.0%)
None26 (52.0%)
Unknown2 (4.0%)

Top CVEs

Signals from CVEs in this product scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu
Jun 3, 20229.899YESYES
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Conflu
Aug 30, 20219.899YESYES
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from
Mar 25, 20199.899YESYES
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using
Jan 16, 20249.898YESYES
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to re
Oct 31, 20239.898YESYES
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible C
Oct 4, 20239.898YESYES
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and /
Apr 18, 20198.898YESYES
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuse
Jul 20, 20229.897YESYES
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint.
Aug 3, 20215.397YESYES
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, wi
May 21, 20248.888NOYES

Exploit Exposure

Signals from CVEs in this product scope (50 CVEs).

CISA KEV
9 CVEs
18.0% of CVEs· 98th percentile
Metasploit
8 CVEs
16.0% of CVEs· 97th percentile
Nuclei
11 CVEs
22.0% of CVEs· 98th percentile
ExploitDB
6 CVEs
12.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (50 CVEs).

Media Mentions

Signals from CVEs in this product scope (50 CVEs).

Top CNAs Publishing CVEs For Confluence Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.8.118.888.3%01
8.8.018.888.3%01
8.7.218.888.3%01
8.7.118.888.3%01
8.6.019.8100.0%11
7.18.039.535.7%11
7.1.017.80.5%00
6.0.617.54.4%00
6.0.517.54.4%00
6.0.417.54.4%00
6.0.317.54.4%00
6.0.217.54.4%00
6.0.117.54.4%00
6.0.017.54.4%00
5.9.917.53.7%00
5.9.817.53.7%00
5.9.717.53.7%00
5.9.617.53.7%00
5.9.517.53.7%00
5.9.417.53.7%00