CVE-2017-18102: Atlassian Jira Server

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in nested wiki markup.

Affected products

  • Atlassian Jira Server: from 7.5.0, before 7.6.8 (fixed in 7.6.8); from 7.7.0, before 7.7.1 (fixed in 7.7.1); from 8.0.0, before 8.0.22 (fixed in 8.0.22)

Published 2018-04-17. Last modified 2026-06-17.