PoC Index

CVE-2023-22527

KEV RANSOMWARECRITICAL 10.0EPSS 100.0%

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.0
10.0 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
99.98% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2024-01-24, used in ransomware campaigns
Nuclei
critical · CWE-74
Published
2024-01-16
Updated
2025-10-21

Proof-of-concept exploits (26)

Nuclei templates (1)

Metasploit modules (1)

Vulhub environments (1)

Exploit collections (1)

References

Related