← Vulnerability feed

Vulnerability record · CVE-2017-18085 · published 2 February 2018

CVE-2017-18085: Atlassian confluence cross-site scripting vulnerability

Atlassian · Confluence

The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.

6.1 CVSS 3.0 Medium EPSS 0.81% · top 44.8% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
0.81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/103062 Third Party AdvisoryVDB Entry
https://jira.atlassian.com/browse/CONFSERVER-54905 Issue TrackingVendor Advisory
http://www.securityfocus.com/bid/103062 Third Party AdvisoryVDB Entry
https://jira.atlassian.com/browse/CONFSERVER-54905 Issue TrackingVendor Advisory

Track CVE-2017-18085 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3395Atlassian confluence server-side request forgery (ssrf) vulnerabilityThe WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.…EPSS 6.7%9.1CVE-2012-2926Atlassian JIRA and related products XML parser file read and DoSMultiple Atlassian products (JIRA, Confluence, FishEye, Crucible, Bamboo, Crowd) fail to properly restrict the capabilities of third-party XML parser…EPSS 66%analysed8.8CVE-2019-3394Atlassian confluence path traversal vulnerabilityThere was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to ed…EPSS 11%7.8CVE-2019-20406Atlassian confluence uncontrolled search path element vulnerabilityThe usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows …EPSS 0.48%6.5CVE-2019-15006Atlassian confluence improper control of dynamically-managed code vulnerabilityThere was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This pl…EPSS 1.9%6.1CVE-2017-18086Atlassian confluence cross-site scripting vulnerabilityVarious resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site …EPSS 0.81%6.1CVE-2017-16856Atlassian confluence cross-site scripting vulnerabilityThe RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripti…EPSS 0.81%6.1CVE-2016-6283Atlassian confluence cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the…EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2017-18085), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.