Crowd

Vendor:

First CVE: May 22, 2012 · Active for 14 years

24
Total CVEs
More Total CVEs than 95% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 49% of tracked products
4.2%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Crowd over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2012
14 years ago
Most Recent CVE
Jan 28, 2026
177 days ago

CVE Severity & Scoring

Crowd24 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (91.7%)
Unknown2 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (75.0%)
High4 (16.7%)
Unknown2 (8.3%)
User Interaction
None18 (75.0%)
Unknown2 (8.3%)
Required4 (16.7%)
Privileges Required
Low7 (29.2%)
High3 (12.5%)
None12 (50.0%)
Unknown2 (8.3%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests
Jun 3, 20199.898YESYES
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo b
May 22, 20129.182NOYES
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which f
Jul 20, 20229.834NONO
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialize
Dec 9, 20169.832NONO
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in
Nov 17, 20229.830NONO
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests o
Jul 20, 20228.829NONO
The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSI
Mar 29, 20198.126NONO
This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) v
Jan 28, 20267.925NONO
The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI inje
Mar 29, 20197.225NONO
The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different director
Mar 29, 20197.525NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
1 CVE
4.2% of CVEs· 97th percentile
Metasploit
2 CVEs
8.3% of CVEs· 97th percentile
Nuclei
1 CVE
4.2% of CVEs· 97th percentile
ExploitDB
1 CVE
4.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Crowd

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.2.018.81.2%00
5.0.029.33.6%00
3.1.026.31.2%00
2.9.119.84.7%00
2.9.019.84.7%00
2.6.317.51.9%00
2.6.215.81.8%00
2.6.115.81.8%00
2.6.015.81.8%00
2.5.315.81.8%00
2.5.215.81.8%00
2.5.115.81.8%00
2.5.015.81.8%00
2.4.915.81.8%00
2.3.815.81.8%00