Jira Server

Vendor:

First CVE: Jan 8, 2016 · Active for 10 years

143
Total CVEs
More Total CVEs than 99% of tracked products
17.9
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 21% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Jira Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 8, 2016
10 years ago
Most Recent CVE
Oct 22, 2025
278 days ago

CVE Severity & Scoring

Jira Server143 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local3 (2.1%)
Network140 (97.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low138 (96.5%)
High5 (3.5%)
Unknown0 (0.0%)
User Interaction
None80 (55.9%)
Unknown0 (0.0%)
Required63 (44.1%)
Privileges Required
Low37 (25.9%)
High14 (9.8%)
None92 (64.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (143 CVEs).

143 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The
Aug 16, 20215.397YESYES
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely
Aug 9, 20199.897YESYES
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, wi
May 21, 20248.888NOYES
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa e
Sep 17, 20205.388NOYES
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server an
Apr 20, 20229.886NOYES
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendere
May 12, 20215.380NOYES
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request
Sep 11, 20196.578NOYES
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vul
Sep 21, 20205.372NOYES
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote a
May 22, 20197.568NOYES
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read se
Jun 30, 20226.562NONO

Exploit Exposure

Signals from CVEs in this product scope (143 CVEs).

CISA KEV
2 CVEs
1.4% of CVEs· 97th percentile
Metasploit
2 CVEs
1.4% of CVEs· 97th percentile
Nuclei
15 CVEs
10.5% of CVEs· 97th percentile
ExploitDB
3 CVEs
2.1% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (143 CVEs).

Media Mentions

Signals from CVEs in this product scope (143 CVEs).

Top CNAs Publishing CVEs For Jira Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.6.025.21.2%00
8.4.017.211.4%00
8.13.314.31.2%00
8.13.015.40.9%00
8.10.014.31.2%00
7.0.313.11.3%00