Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-22527 — Exploit for CVE-2023-22527 - Atlassian Confluence Data Center and Server | Kitploit
Tools/GitHubGitHub/yoryio/cve-2023-22527
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlRed Teaming
GitHubyoryio/cve-2023-22527

CVE-2023-22527

Exploit for CVE-2023-22527 - Atlassian Confluence Data Center and Server

View Repository
4112 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-22527

CVE-2023-22527 - Server-side Template Injection (SSTI) vulnerability allowing Remote Code Execution (RCE) In Confluence Data Center and Confluence Server

image

Products and Versions affected:

ProductAffected Versions
Confluence Data Center and Server8.0.x
8.2.x
8.3.x
8.4.x
8.5.0-8.5.3
  • CVSS: 10.0
  • Actively Exploited: YES
  • Patch: YES
  • Mitigation: NO

Help

root@kitploit:~
usage: CVE-2023-22527.py [-h] -u URL [-c COMMAND]

options:
  -h, --help            show this help message and exit
  -u URL, --url URL     Atlassian Confluence Server URL
  -c COMMAND, --command COMMAND
                        Command to Execute

Example: python CVE-2023-22527.py -u https://10.10.12.2 -c whoami

Lab

You can use Try Hack Me's Room Confluence CVE-2023-22515 to test the exploit because it also runs a vulnerable version affected by CVE-2023-22527.

Vision of Atlassian Confluence Servers by SHADOWSERVER:

map

References

  • Where are they now? Starring: Confluence CVE-2023-22527
  • Atlassian Confluence - Remote Code Execution (CVE-2023-22527)
  • Shadowserver Atlassian Statistics
  • CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server
  • GreyNoise Tag - Atlassian Confluence Template Injection RCE Attempt
  • CISA Adds One Known Exploited Vulnerability to Catalog
Download Tool