Atlassian

Jira

158 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.78%
  • Veröffentlicht 10.04.2017 03:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.

  • EPSS 0.67%
  • Veröffentlicht 10.04.2017 03:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

Exploit
  • EPSS 2.11%
  • Veröffentlicht 31.01.2017 22:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

  • EPSS 2.08%
  • Veröffentlicht 09.03.2014 13:16:57
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.

Exploit
  • EPSS 26.15%
  • Veröffentlicht 09.03.2014 13:16:57
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.

Exploit
  • EPSS 2.15%
  • Veröffentlicht 20.08.2013 14:55:47
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in Atlassian JIRA before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via the name parameter to secure/admin/user/Del...

  • EPSS 66.58%
  • Veröffentlicht 22.05.2012 15:55:02
  • Zuletzt bearbeitet 16.06.2026 23:42:22

Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before...

  • EPSS 3.06%
  • Veröffentlicht 22.05.2012 15:55:02
  • Zuletzt bearbeitet 16.06.2026 23:42:22

The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (re...

  • EPSS 2.24%
  • Veröffentlicht 20.04.2010 15:30:00
  • Zuletzt bearbeitet 16.06.2026 23:17:38

Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) element or (2) defaultColor parameter to the Colour Picker page; the (3) formName paramet...

  • EPSS 4.44%
  • Veröffentlicht 20.04.2010 15:30:00
  • Zuletzt bearbeitet 16.06.2026 23:17:38

Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka attachments), (2) index (aka indexing), or (3) backup path and then uploading a file, as exploited in the wild i...