Jira Align
Vendor:
First CVE: Oct 14, 2022 · Active for 3 years
13
Total CVEs
More Total CVEs than 92% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
4.9
Avg CVSS
Higher Avg CVSS than 8% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jira Align over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 14, 2022
3 years ago
Most Recent CVE
Oct 22, 2025
279 days ago
CVE Severity & Scoring
Jira Align13 CVEs
92%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low12 (92.3%)
High1 (7.7%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36803HIGH The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modi | Oct 14, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-22175MEDIUM Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-l | Oct 22, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-22173MEDIUM Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-l | Oct 22, 2025 | 4.3 | 20 | NO | NO |
CVE-2025-22169MEDIUM Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-l | Oct 22, 2025 | 5.4 | 20 | NO | NO |
CVE-2022-36802MEDIUM The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Re | Oct 14, 2022 | 4.9 | 19 | NO | NO |
CVE-2025-22178MEDIUM Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-l | Oct 22, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-22177MEDIUM Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-l | Oct 22, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-22176MEDIUM Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-l | Oct 22, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-22174MEDIUM Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-l | Oct 22, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-22172MEDIUM Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-l | Oct 22, 2025 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Jira Align
Top CWEs
Versions
No cataloged versions.