The Adaptavist Group LogoDocumentation

Release Notes

Check out what's new for Mosaic for Server and DC.

Warning:Confluence version warning. Confluence version 9.3.2 contains a known error that affects a number of apps, including Mosaic. To avoid issues we recommend upgrading to version 9.4

8.1.4

17th September 2026

Security Patch

Fixed a security vulnerability
Tip: We recommend upgrading to this version or later versions.

Compatibility with Confluence 9.2.24

We've resolved a compatibility issue that affected Mosaic on Confluence 9.2.24. Atlassian has also addressed the underlying issue in later Confluence releases.

Fixes

  • The TOC macro now correctly includes the conent from Excerpt Include regardless of the contents of any linked HTML comments.

  • Background macros nested inside Alert macros now work as expected.

  • The Blueprint helper now correctly respects the users permissions.

  • The following macros now work as expected

9.0.5

14th September 2026

Security Patch

Fixed a security vulnerability

Tip: We recommend upgrading to this version or later versions.

Compatibility with Confluence 10.2.16 and 10.2.17

We've resolved a compatibility issue that affected Mosaic on Confluence 10.2.16 and 10.2.17. Atlassian has also addressed the underlying issue in later Confluence releases.

Fixes

  • The TOC macro now correctly includes the conent from Excerpt Include regardless of the contents of any linked HTML comments.

  • Background macros nested inside Alert macros now work as expected.

  • The Blueprint helper now correctly respects the users permissions.

  • The following macros now work as expected

9.0.4

15th July 2026

Security Patch

Fixed a security vulnerability
Tip: We recommend upgrading to this version or later versions.

Fixes

8.1.2

2nd May 2026

Security patch

Fixed a security vulnerability.

Tip: We recommend upgrading to this version or later versions.

Fixes

  • When clicked Lozenge macros now correctly take users to the chosen destination.

9.0.3

2nd March 2026

Security patch

Fixed a security vulnerability.

Tip: We recommend upgrading to this version or later versions.

8.1.1

16th October 2025

Fixes

  • The Alert macro no longer prevents Inline comments from working.
  • Fixed an issue where the CSS macro was not working on all nodes in some circumstances.
  • We have resolved an issue where the Macro Usage Report was not handling some macros correctly, it now provides a detailed error message.

9.0.2

16th October 2025

Fixes

  • The Alert macro no longer prevents Inline comments from working.
  • Fixed an issue where the CSS macro was not working on all nodes in some circumstances.

8.1.0

17th September 2025

Macro Usage Report

To help you prepare for migrating from Confluence Data Center to Cloud, we've introduced the new Macro Usage Report. This report identifies all pages that use macros and which macros are being used on those pages, including those that may not be supported in Confluence Cloud.

With this report, you can:

  • Identify pages that contain Mosaic macros
  • Understand potential compatibility risks
  • Take action before migration to avoid broken or missing content in Cloud

This feature ensures you have the visibility you need to plan a smoother, more reliable migration experience.

9.0.1

4th September 2025

Security Update

CVE-2025-53864 - Third-Party Library Vulnerability Update

A vulnerability was discovered within a third party library that is used by Mosaic.

CVE : https://nvd.nist.gov/vuln/detail/CVE-2025-53864

Library Name: nimbus-jose-jwt

Affected Library Version: v9.37.3

Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.

Action Taken

To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.

Recommendations

  1. We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
  2. More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-53864

CVE-2025-48924 - Third-Party Library Vulnerability Update

A vulnerability was discovered within a third party library that is used by Mosaic.

CVE : https://nvd.nist.gov/vuln/detail/CVE-2025-48924

Library Name: commons-lang

Affected Library Version: v2.6 & v-3.12.0

Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.

Action Taken

To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.

Recommendations

  1. We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
  2. More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-48924

Third-Party Library Vulnerability Update

A vulnerability was discovered within a third party library that is used by Mosaic.

Library Name: image-size

Affected Library Version: >= 1.1.0, < 1.2.1 and >= 2.0.0, < 2.0.2

Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.

Action Taken

To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.

Recommendations

We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.

8.0.14

4th September 2025
Warning: This version is only compatible with Confluence 8 and 9

Security Update

CVE-2025-53864 - Third-Party Library Vulnerability Update

A vulnerability was discovered within a third party library that is used by Mosaic.

CVE : https://nvd.nist.gov/vuln/detail/CVE-2025-53864

Library Name: nimbus-jose-jwt

Affected Library Version: v9.37.3

Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.

Action Taken

To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.

Recommendations

  1. We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
  2. More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-53864

CVE-2025-48924 - Third-Party Library Vulnerability Update

A vulnerability was discovered within a third party library that is used by Mosaic.

CVE : https://nvd.nist.gov/vuln/detail/CVE-2025-48924

Library Name: commons-lang

Affected Library Version: v2.6 & v-3.12.0

Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.

Action Taken

To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.

Recommendations

  1. We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
  2. More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-48924

Third-Party Library Vulnerability Update

A vulnerability was discovered within a third party library that is used by Mosaic.

Library Name: image-size

Affected Library Version: >= 1.1.0, < 1.2.1 and >= 2.0.0, < 2.0.2

Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.

Action Taken

To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.

Recommendations

We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.

8.0.13

This version is only compatible with Confluence 8 and 9.

25th August 2025

Fixes

  • In a small number of cases it was possible to bypass the URL allowlist. This has now been resolved.

9.0.0

11th August 2025

Updates

  • Compatibility updates for Confluence 10.

Fixes

  • In a small number of cases it was possible to bypass the URL allowlist. This has now been resolved.

8.0.12

31st July 2025

Security Update

CVE-2025-48734 - Third-Party Library Vulnerability Update

A vulnerability was discovered within a third party library that is used by Mosaic for Confluence.

CVE :https://nvd.nist.gov/vuln/detail/CVE-2025-48734

Library Name: Apache commons-beanutils

Affected Library Version: v1.9.4

Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.

Action Taken

To minimize the risk, we have updated the version of the library that Mosaic for Confluence uses. We have selected a version that has no known vulnerabilities.

Recommendations

  1. We always recommend updating to the latest version of Mosaic for Confluence to ensure you are running the latest and most secure software.
  2. More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-48734.

CVE-2025-5878 - Third-Party Library Vulnerability Update

A vulnerability was discovered within a third party library that is used by Mosaic for Confluence.

CVE :https://nvd.nist.gov/vuln/detail/CVE-2023-5878

Library Name: ESAPI

Affected Library Version: v2.6.0

Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.

Action Taken

To minimize the risk, we have updated the version of the library that Mosaic for Confluence uses. We have selected a version that has no known vulnerabilities.

Recommendations

  1. We always recommend updating to the latest version of Mosaic for Confluence to ensure you are running the latest and most secure software.
  2. More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2023-5878.

8.0.11

12th June 2025

Fixes

  • Fixed an issue where the Search Box macro was occasionally leading to performance issues.

8.0.10

26th March 2025

Fixes

  • The iframe Macro no longer shows a system error when opened.

8.0.9

5th March 2025

Fixes

  • Made a security fix.
  • Help links from all macros now take you to the correct page in the documentation.
  • The iframe macro now works as expected in all version of Confluence 9.
  • Tabs with lazy loading enabled now correctly load their content.
  • The Clickable macro now displays and works as expected.
  • Users can now create multiple pages using the Blog template without issue.

8.0.8

30th January 2025

Updates

Updates

  • We're excited to announce that Content Formatting Macros is starting the new year with a new name - Mosaic for Confluence. We are very proud of how much Content Formatting Macros has grown and changed over the years. This new name represents the latest phase in our journey as we continue to strive to give our users the best tools to get the most out of Confluence.

Fixes

  • Made a security update.

8.0.7

22nd January 2025

Fixes

  • The CSS Style sheet macro no longer causes a html comment to appear when it is added to a page.
  • The link to manage our app from the Manage App screen no longer gives a 404 error.
  • Fixed issues where tables did not display as expected when combined with tabs or other rich macros.

8.0.6

16th December 2024

Urgent Update

Unfortunately an issue was present in versions 8.0.3, 8.0.4, and 8.0.5. This issue led to the loss of content inside HTML Comment macros. If you are using one of these versions we recommend updating to version 8.0.6 as soon as possible.To avoid loss of content inside these macros we recommend taking the following steps.

  1. Copy content from any HTML Comment macros in your instance.
  2. Upgrade to version 8.0.6.
  3. If required, copy missing content into HTML Comment macros.

Updates

  • Made a number of security updates.

Fixes

  • HTML Comments now show as expected.
  • Fixed an issue where CSS Stylesheet was changing the color of buttons from 3rd party apps.
  • Table headers now show as expected.
  • The first rows of tables now respect the type of cell used.

8.0.2

29th October 2024

Fixes

  • CSS styles are no longer incorrectly applied to buttons within forms.
  • Made a security update.

8.0.1

7th October 2024

Fixes

  • Fixed an issue that was causing data inside tables in tabs to be formatted as buttons.
  • Fixed an issue where the Rollover macro was not correctly redirecting to some links.
  • The following content is now correctly displayed within the Alert macro
    • Tables
    • Buttons
    • User Tags
    • Links
    • Profile Picture macro content
  • Fixed an issue where HTML table was not displaying correctly
  • Resolved an issues where CSS Style Sheet did not work as expected when used with a third party app.

8.0.0

5th August 2024

Updates

  • Compatibility updates for Confluence 9.

7.2.7

30th May 2024

Fixes

  • Made a security update.
  • Fixed an issue where formatting inside the Alert macro was not working as expected.
Tip: We recommend updating to this version as soon as possible.

7.2.6

15th May 2024

Fixes

  • Fixed an issue where the Rollover macro was not displaying images.
  • Made a security update.

We recommend updating to this version as soon as possible.

6.6.5

15th May 2024

CAUTION: This release is compatible with Confluence 7 only. It is NOT compatible with Confluence 8.

Fixes

  • Fixed an issue where the Rollover macro was not displaying images.

7.2.5

2nd April 2024

Updates

  • We have made several updates to the way our app works in preparation for the release of Confluence 9.

Fixes

  • Minor security improvements have been made by updating 3rd party software to versions with no known vulnerabilities.
    • A number of 3rd party libraries have been identified to have vulnerabilities. While the vulnerable components of these libraries are not used, the libraries have been patched to a version with no identified vulnerabilities to prevent accidental use of the components in the future.

6.6.4

2nd April 2024

Warning: This release is compatible with Confluence 7 only. It is NOT compatible with Confluence 8.

Fixes

  • Minor security improvements have been made by updating 3rd party software to versions with no known vulnerabilities.
    • A number of 3rd party libraries have been identified to have vulnerabilities. While the vulnerable components of these libraries are not used, the libraries have been patched to a version with no identified vulnerabilities to prevent accidental use of the components in the future.

7.2.4

20th November 2023

Fixes

  • Minor security improvements have been made by updating 3rd party software to versions with no known vulnerabilities.
    • During an audit of 3rd party software used by Content Formatting Macros for Confluence, some were found to have vulnerabilities. Investigating the concerns showed that Content Formatting Macros used no vulnerable components for Confluence, regardless we have updated the version used.

6.6.3

20th November 2023
CAUTION: This release is compatible with Confluence 7 only. It is NOT compatible with Confluence 8

Fixes

  • Minor security improvements have been made by updating 3rd party software to versions with no known vulnerabilities.
    • During an audit of 3rd party software used by Content Formatting Macros for Confluence, some were found to have vulnerabilities. Investigating the concerns showed that Content Formatting Macros used no vulnerable components for Confluence, regardless we have updated the version used.

7.2.3

4th August 2023

Re-release of 7.2.2.

6.6.1

24th July 2023
CAUTION: This release is compatible with Confluence 7 only. It is NOT compatible with Confluence 8.

Bug Fixes

Fixed a bug where the CSS style sheet macro was changing the appearance of buttons.

7.2.2

15th June 2023

Fixes

Compatability updates for Confluence 8.3

7.2.1

26th May 2023

Fixes

  • Compatability updates for Confluence 8.3
  • Fix for a bug affecting the footnotes macro

7.2.0

3rd May 2023

Update

In-app rebranding changes

7.1.1

5th April 2023

Update

Rebranding changes

Your favorite macros have a new look.

We're excited to tell you that Content Formatting Macros for Confluence is now part of Kolekti, a new brand under The Adaptavist Group.

We've updated our apps and macros with a fresh new color - we hope you like the new look.

The app (and our team!) are still the same. We'll keep working hard to give you market-leading tools and support you can rely on.

7.0.2

21st March 2023

Update

Compatibility with Confluence 8.1

Note:

There is a minor issue with rendering the table head(th) macro due to a change that Atlassian introduced:

  • The issue affects the styling capabilities of the macro, so the table content may present appear different than expected in publish mode.
  • Data won't be lost; content and configuration will be accessible as usual in edit mode.

We have escalated the issue with the highest priority with Atlassian and hope to have an update shortly. In addition, our team is working to achieve full compatibility. Once resolved, we will release a new version of the app.

7.0.1

3rd February 2023

Fixes

Fix to ensure correct display of text in the Button macro

7.0.0

19th January 2023

Update

Compatibility with Confluence 8

This update is only compatible with Confluence 8. It is not backward compatible.

6.6.0

26th October 2022

Fixes

Security update to address vulnerabilities

Fix made to tabs to allow them to be viewed anonymously when lazy loading is enabled.

6.5.3

10th October 2022

Fixes

Security update to address vulnerabilities

Update

In response to a request, Improvements have been made to log output from the CSS Stylesheet Macro. This will allow Admins to find the location of CSS errors within stylesheets more easily.

6.5.1

9th August 2022

Fixes

Security update to address vulnerabilities

6.5.0

27th July 2022

Fixes

Security update to address Atlassian Vulnerability

6.4.26

13th June 2022

Updates

  • Improvements made to the copy in the macro editors to improve the user experience.
  • Search information update for macros to make it easier to find the macro you need.
  • Colgroup Marco deprecated.

6.4.25

4th April 2022

Fixes

  • Correcting description for the Search Box Macro
  • Security Patch: Fixed XSS vulnerabilities in Rollover and Progress Bar Macros

6.4.23

16th February 2022

Fixes

  • Minor Bug Fix
  • Updating MathJax to the latest version

6.4.21

26th January 2022

Fixes

  • Fixed an issue with Tooltip in Confluence 7.12
  • Fixed a minor bug in Footnote's rendering of backslashes
  • Security Patch: Fixed XSS vulnerabilities

6.4.20

25 November 2021

Fixes

  • Corrected error on colgroup with CSS

6.4.19

12 October 2021

Fixes

  • Minor Bug Fix

6.4.18

6 October 2021

CAUTION: A security vulnerability was discovered with the rollover macro, so customers should download version 6.4.18 or later to resolve this.

Fixes

  • Fixed a security vulnerability with the Rollover Macro

6.4.17

23 September 2021

Fixes

  • Updated in-app links for new documentation site

6.4.16

3 August 2021

Analytics Update

  • Improved analytics to help determine areas to improve value to the customer

6.4.15

8 July 2021

Fixes

  • Fixed Latex issue on instance hosted on AWS
  • Made Bibtex display order the same as page order
  • Fixed Footnotes not showing backslashes

6.4.14

23 June 2021

Fixes

  • Fixed menu bar not sticking
  • Fixed issue with links in footnotes

6.4.13

13 May 2021

Updates

  • Compatibility with Confluence 7.12.0

Fixes

  • Resolved Dialog macro issue to make it compatible with AUI 9
  • Footnote macro tooltip now shows on hover for Confluence 7.12.0

6.4.11

20 April 2021

Analytics Update

  • Improved analytics to help determine areas to improve value to the customer

Fixes

  • Updated in-app links for new documentation site

6.4.10

12 April 2021

Fixes

  • Updated in-app links for new documentation site

6.4.9

23 March 2021

Analytics Update

  • Improved analytics to help determine areas to improve value to the customer

6.4.8

12 March 2021

What's new

  • Analytics Update: Updated the analytics architecture to improve reporting

6.4.7

17 Nov 2020

Fixes

  • Security patch: Fixed a security vulnerability and other minor fixes

    We recommend upgrading to this version or later versions.

6.4.6

13 Oct 2020

Compatible with Confluence Server and Confluence Data Center 6.13.0-7.9.3

Fixes

  • Security patch: Replaced a third-party library that contained a vulnerability

    We recommend upgrading to this version or later versions.

6.4.5

15 April 2020

Compatible with Confluence Data Center 6.12.0-7.7.4

What's new

  • Data Center Read-only Mode compatibility

6.4.4

18 Feb 2020

Fixes

  • Fixed an issue where logging was being blocked in versions 6.3.2-6.3.3.

6.4.3

09 Dec 2019

Fixes

  • Fixed an issue where relative URLs were not being supported by the Confluence whitelist for Style Sheet macro (CONTENTF-1160).
  • Made improvements to our in-product analytics.

6.4.2

26 Nov 2019

Fixes

  • Fixed an issue with certain macros and Tomcat configuration (CONTENTF-1131).

6.4.1

21 Nov 2019

Fixes

  • Patched a vulnerability that was affecting the Style Sheet macro. This vulnerability is classed as high according to Atlassian's security severity levels. More information can be found in our public ticket, (CONTENTF-1150). We recommend customers update to version 6.4.1 of Content Formatting Macros for Confluence as soon as possible. If you are unable to upgrade at this time we recommend that you disable the Style Sheet macro from the universal plug-in manager.

6.4.0

02 Oct 2019

What's new

  • Introduced a new system of gathering anonymous analytics to gain insight into how it is used with the aim of improving user experience. For more information, please see the Analytics topic in our documentation.

6.3.5

17 Sep 2019

Fixes

Note: We strongly recommend customers update to version 6.3.5 of Content Formatting Macros for Confluence as soon as possible. If customers are unable to upgrade at this time, we recommend that they disable the LaTeX macro and the Restful Table macro from the universal plug-in manager.

6.3.4

10 Jul 2019

Fixes

  • Fixed an issue when Iframe macro without a URL caused import tool to hang at 0% ( CONTENTF-1036)
  • Fixed documentation links on the configuration menu for Alert, Colgroup Tag, and Tooltip macros

6.3.3

06 Jun 2019

What's new

  • Reworked Footnotes Macro to make exporting content with footnotes more usable in MS Word and PDF (CONTENTF-306)

Fixes

  • Fixed an issue where line breaks were being ignored with the Highlight Macro (CONTENTF-87)

6.3.2

13 May 2019

Fixes

  • Increased the URL limit to 2000 characters in the Iframe Configuration feature, which fixed an issue where the URL Import Tool would not complete if it encountered a long URL. ( CONTENTF-316)
  • Fixed an issue with version 6.3.1 of Content Formatting where the LaTeX macro would not render ( CONTENTF-317)

6.3.1

02 May 2019

We strongly recommend customers update to version 6.3.1 of Content Formatting as soon as possible. If customers are unable to upgrade at this time we recommend that they disable the Iframe macro module in the Content Formatting for Confluence section of the Confluence app menu.

  • Added Iframe Macro Configuration feature to resolve security vulnerability
    • Will automatically add the sandbox attribute to all Iframes and give Confluence Administrators the ability to allow, sandbox, or deny iframes.
  • Fixed a security vulnerability ( CONTENTF-223)

6.2.9

31 Jan 2019

CAUTION: A security vulnerability was discovered with the Iframe macro, so customers should download a version 6.3.1 or later to resolve this. If customers need to download this version, we advise disabling the Iframe macro module.

What's new

  • Updated 3rd party libraries containing a security patch.
  • Made Content Formatting compatible with Confluence version 6.14.
  • Added a new getting started page for Confluence Admins.

6.2.8

23 Jan 2019

Warning: A security vulnerability was discovered with the Iframe macro, so customers should download a version 6.3.1 or later to resolve this. If customers need to download this version, we advise disabling the Iframe macro module.

What's new

  • Enabled mobile compatibility

Fixes

  • Fixed a problem where the Button Hyperlink macro causes an error when target page title includes '/' (CONTENTF-130)

  • Fixed a problem where users weren't able to create an AUI Button that had a file link to a network driver as the target URL (CONTENTF-142)

6.2.6

25 Oct 2018

Warning: A security vulnerability was discovered with the Iframe macro, so customers should download a version 6.3.1 or later to resolve this. If customers need to download this version, we advise disabling the Iframe macro module.

Fixes

  • Fixed minor bugs and compatibility with Confluence 6.12

6.2.5

03 Oct 2018

Warning: A security vulnerability was discovered with the Iframe macro, so customers should download a version 6.3.1 or later to resolve this. If customers need to download this version, we advise disabling the Iframe macro module.

What's new

  • Upgraded Jackson Databind library to patch CVE-2018-7489, which is a recommended upgrade for all Content Formatting for Confluence users.

Search documentation

Start typing to search the docs.