CVE-2023-36662: Techtime User Management

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through 2.15.24.

Affected products

  • Techtime User Management: from 2.0.0, up to and including 2.15.24; from 2.0.0, up to and including 2.17.1; from 2.2.2, up to and including 2.15.24

Published 2023-06-26. Last modified 2026-06-17.