159 exploited vulnerabilities in Confluence
- Vendors
- Apache, Atlassian, Linux Mint, Red Os, Canonical, Npm
- With known exploits
- 159
- Affected Apache Tomcat versions
- β€ 7.0.109, 8.5.100, 9.0.118, 10.1.55, 11.0.22, 9.0.104, 10.1.40, 11.0.6, 11.0.0, 9.0.98, 10.1.34, 11.0.2, 9.0.116, 10.1.53, 11.0.20, 10.1.0
- Affected Axios versions
- < 0.31.1, 1.15.1, 0.31.0, 1.15.0, 1.16.0
- Affected Apache Tika versions
- < 3.2.2
- Affected Apache Commons Configuration versions
- < 2.10.1
- Affected Postgresql Postgresql Jdbc Driver versions
- < 42.2.28, 42.3.9, 42.4.4, 42.5.5, 42.6.1, 42.7.2
- Affected Atlassian Confluence Data Center versions
- < 8.5.4, 8.7.0, 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.0, 8.3.3, 8.4.3, 8.5.2, 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.0, 6.13.23, 7.4.11, 7.11.6, 7.12.5
- Affected Atlassian Confluence Server versions
- < 8.3.3, 8.4.3, 8.5.2, 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.0, 6.13.23, 7.4.11, 7.11.6, 7.12.5, 6.6.12, 6.12.3, 6.13.3, 6.14.2
- Affected Snakeyaml Project Snakeyaml versions
- < 2.0
Vulnerabilities with exploits
Highest CVSS first β 23 of these already have exploit code on Sploitus
CVE-2026-43512 1 exploit
CVE-2026-41293
CVE-2026-42043
CVE-2026-40175 4 exploits
CVE-2025-66516 5 exploits
Exploit for Improper Restriction of XML External Entity Reference in Apache TikaExploit for CVE-2025-66516
CVE-2025-54988 4 exploits
CVE-2025-48387
CVE-2025-31650 5 exploits
CVE-2024-50379 13 exploits
Exploit for Time-of-check Time-of-use (TOCTOU) Race Condition in Apache TomcatExploit for CVE-2025-55752
CVE-2024-29415
CVE-2024-29131
CVE-2024-29133
CVE-2023-42282
CVE-2024-1597
CVE-2023-22527 32 exploits
CVE-2023-22518 13 exploits
Exploit for Incorrect Authorization in Atlassian Confluence_Data_CenterExploit for Incorrect Authorization in Atlassian Confluence_Data_Center
CVE-2023-22515 38 exploits
Exploit for Improper Input Validation in Atlassian Confluence_Data_CenterExploit for Improper Input Validation in Atlassian Confluence_Data_Center
CVE-2022-1471 9 exploits
Exploit for Deserialization of Untrusted Data in Snakeyaml_Project SnakeyamlExploit for Deserialization of Untrusted Data in Snakeyaml_Project Snakeyaml
CVE-2022-26134 76 exploits
Exploit for Expression Language Injection in Atlassian Confluence_Data_CenterExploit for Expression Language Injection in Atlassian Confluence_Data_Center
CVE-2021-26084 44 exploits
Exploit for Expression Language Injection in Atlassian Confluence_Data_CenterExploit for Expression Language Injection in Atlassian Confluence_Data_Center
CVE-2019-3396 19 exploits
Exploit for Path Traversal in Atlassian Confluence_ServerExploit for Expression Language Injection in Atlassian Confluence_Data_Center
CVE-2026-42585
CVE-2026-2332
CVE-2026-4800
CVE-2026-33871
CVE-2026-29063
CVE-2024-56337 1 exploit
CVE-2024-47561
CVE-2022-37601
CVE-2022-45143
CVE-2022-42252
CVE-2022-26138 1 exploit
CVE-2026-44494
CVE-2026-43515 1 exploit
CVE-2026-42584
CVE-2026-29145 2 exploits
Exploit for Improper Authentication in Apache TomcatExploit for Improper Authentication in Apache Tomcat
CVE-2024-22871
CVE-2024-22259 1 exploit
CVE-2024-22243 1 exploit
CVE-2022-1231
CVE-2026-42579
CVE-2026-42264
CVE-2025-62718
CVE-2026-23950
CVE-2024-21683 9 exploits
Exploit for Code Injection in Atlassian Confluence_Data_CenterAtlassian Confluence Administrator Code Macro Remote Code Execution Exploit
CVE-2022-46175
CVE-2019-3398 9 exploits
Atlassian Confluence 6.15.1 - Directory Traversal VulnerabilityAtlassian Confluence 6.15.1 - Directory Traversal Exploit
CVE-2025-53689
CVE-2024-4367 16 exploits
Exploit for Improper Check for Unusual or Exceptional Conditions in Mozilla FirefoxExploit for Improper Check for Unusual or Exceptional Conditions in Mozilla Firefox
CVE-2019-3394 1 exploit