Crowd
Vendor:
First CVE: May 22, 2012 · Active for 14 years
24
Total CVEs
More Total CVEs than 95% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 49% of tracked products
4.2%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Crowd over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2012
14 years ago
Most Recent CVE
Jan 28, 2026
177 days ago
CVE Severity & Scoring
Crowd24 CVEs
38%
42%
21%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (91.7%)
Unknown2 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (75.0%)
High4 (16.7%)
Unknown2 (8.3%)
User Interaction
None18 (75.0%)
Unknown2 (8.3%)
Required4 (16.7%)
Privileges Required
Low7 (29.2%)
High3 (12.5%)
None12 (50.0%)
Unknown2 (8.3%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11580CRITICAL Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests | Jun 3, 2019 | 9.8 | 98 | YES | YES |
CVE-2012-2926CRITICAL Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo b | May 22, 2012 | 9.1 | 82 | NO | YES |
CVE-2022-26136CRITICAL A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which f | Jul 20, 2022 | 9.8 | 34 | NO | NO |
CVE-2016-6496CRITICAL The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialize | Dec 9, 2016 | 9.8 | 32 | NO | NO |
CVE-2022-43782CRITICAL Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in | Nov 17, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-26137HIGH A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests o | Jul 20, 2022 | 8.8 | 29 | NO | NO |
CVE-2017-18105HIGH The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSI | Mar 29, 2019 | 8.1 | 26 | NO | NO |
CVE-2026-21569HIGH This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server.
This XXE (XML External Entity Injection) v | Jan 28, 2026 | 7.9 | 25 | NO | NO |
CVE-2017-18108HIGH The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI inje | Mar 29, 2019 | 7.2 | 25 | NO | NO |
CVE-2017-18106HIGH The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different director | Mar 29, 2019 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
1 CVE
4.2% of CVEs· 97th percentile
Metasploit
2 CVEs
8.3% of CVEs· 97th percentile
Nuclei
1 CVE
4.2% of CVEs· 97th percentile
ExploitDB
1 CVE
4.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Crowd
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.2.0 | 1 | 8.8 | 1.2% | 0 | 0 |
| 5.0.0 | 2 | 9.3 | 3.6% | 0 | 0 |
| 3.1.0 | 2 | 6.3 | 1.2% | 0 | 0 |
| 2.9.1 | 1 | 9.8 | 4.7% | 0 | 0 |
| 2.9.0 | 1 | 9.8 | 4.7% | 0 | 0 |
| 2.6.3 | 1 | 7.5 | 1.9% | 0 | 0 |
| 2.6.2 | 1 | 5.8 | 1.8% | 0 | 0 |
| 2.6.1 | 1 | 5.8 | 1.8% | 0 | 0 |
| 2.6.0 | 1 | 5.8 | 1.8% | 0 | 0 |
| 2.5.3 | 1 | 5.8 | 1.8% | 0 | 0 |
| 2.5.2 | 1 | 5.8 | 1.8% | 0 | 0 |
| 2.5.1 | 1 | 5.8 | 1.8% | 0 | 0 |
| 2.5.0 | 1 | 5.8 | 1.8% | 0 | 0 |
| 2.4.9 | 1 | 5.8 | 1.8% | 0 | 0 |
| 2.3.8 | 1 | 5.8 | 1.8% | 0 | 0 |