CVE-2019-11581
Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
- Published
- Aug 9, 2019
- Updated
- Oct 21, 2025
- Assigning CNA
- atlassian
- Evidence observed
- Mar 7, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
Sources
3- CVE-2019-11581Exploit
Atlassian JIRA Template injection vulnerability RCE
Proof-of-concept exploit for CVE-2019-11581 targeting Atlassian Jira Server and Data Center. Demonstrates unauthenticated remote code execution via template injection.
- CVE-2019-11581Exploit
Atlassian Jira unauthen template injection
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.