Products: 4
    Vulnerabilities: 4
    Known Exploited: 0
    2
    Critical Level Threats
    0
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-12225

    syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent

    Last Modified: Jun 23, 2026
    Published: Jun 16, 2026

    CVE-2024-48941

    The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.

    Last Modified: Oct 11, 2024
    Published: Oct 09, 2024

    CVE-2024-48942

    The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.

    Last Modified: Oct 11, 2024
    Published: Oct 09, 2024

    CVE-2023-22958

    The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter.

    Last Modified: Apr 07, 2025
    Published: Jan 11, 2023
    Items Per Page
    Syracom Vulnerabilities & Security CVEs | CVE-DB