CVE-2021-26078 EXPLOIT
6.1
MEDIUM · CVSS 3.1 · EPSS 4% (pctl 90)
Patch early
A public exploit exists.
Description
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
Scoring
| CVSS | 6.1 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 4.03% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-06-07 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| atlassian | data center |
| atlassian | jira |
| atlassian | jira server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Atlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS) | 2021-06-28 |
References
- http://packetstormsecurity.com/files/163289/Atlassian-Jira-Server-Data-Center-8.16.0-Cross-Site-Scripting.html
- https://jira.atlassian.com/browse/JRASERVER-72392
- http://packetstormsecurity.com/files/163289/Atlassian-Jira-Server-Data-Center-8.16.0-Cross-Site-Scripting.html
- https://jira.atlassian.com/browse/JRASERVER-72392
→ the Explorer · watch your stack · NVD