CVE-2019-15053: Atlassian Html Include And Replace Macro

Medium severity, CVSS 6.8. EPSS: 1.3% chance of exploitation in the next 30 days.

The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.

Affected products

  • Atlassian Html Include And Replace Macro: from 1.1, up to and including 1.4.2

Published 2019-08-14. Last modified 2026-06-17.