CVE-2019-3396
CWE-22
103.8
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
Source: NVD
Signals
- CVSS
- 9.8
- Critical · v3.1
- EPSS
- 99.91%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Nov 2021
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-22
- Published
- 25 Mar 2019
- Last modified 24 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2019-3396Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time