Release Notes
Check out what's new for Mosaic for Server and DC.
8.1.4
17th September 2026
Security Patch
Compatibility with Confluence 9.2.24
We've resolved a compatibility issue that affected Mosaic on Confluence 9.2.24. Atlassian has also addressed the underlying issue in later Confluence releases.
Fixes
The TOC macro now correctly includes the conent from Excerpt Include regardless of the contents of any linked HTML comments.
Background macros nested inside Alert macros now work as expected.
The Blueprint helper now correctly respects the users permissions.
The following macros now work as expected
9.0.5
14th September 2026
Security Patch
Fixed a security vulnerability
Compatibility with Confluence 10.2.16 and 10.2.17
We've resolved a compatibility issue that affected Mosaic on Confluence 10.2.16 and 10.2.17. Atlassian has also addressed the underlying issue in later Confluence releases.
Fixes
The TOC macro now correctly includes the conent from Excerpt Include regardless of the contents of any linked HTML comments.
Background macros nested inside Alert macros now work as expected.
The Blueprint helper now correctly respects the users permissions.
The following macros now work as expected
9.0.4
15th July 2026
Security Patch
Fixes
- The previews in the following m across now correctly show the content
- The Strikethrough macro now correctly applies to the content inside it.
- The CSS Macro no longer shifts the position of the page title.
8.1.3
6th May 2026
Fixes
The preview in the following macros now works as expected.
The Strikethrough macro now correctly applues the strikethough effect to text.
The Clickable macro crrectly displayes its content regardless of the location set for the URL
The CSS Style Sheet macro no longer unintentionally affects the layout of the page and page title.
8.1.2
2nd May 2026
Security patch
Fixed a security vulnerability.
Fixes
When clicked Lozenge macros now correctly take users to the chosen destination.
9.0.3
2nd March 2026
Security patch
Fixed a security vulnerability.
8.1.1
16th October 2025
Fixes
- The Alert macro no longer prevents Inline comments from working.
- Fixed an issue where the CSS macro was not working on all nodes in some circumstances.
- We have resolved an issue where the Macro Usage Report was not handling some macros correctly, it now provides a detailed error message.
9.0.2
16th October 2025
Fixes
- The Alert macro no longer prevents Inline comments from working.
- Fixed an issue where the CSS macro was not working on all nodes in some circumstances.
8.1.0
17th September 2025
Macro Usage Report
To help you prepare for migrating from Confluence Data Center to Cloud, we've introduced the new Macro Usage Report. This report identifies all pages that use macros and which macros are being used on those pages, including those that may not be supported in Confluence Cloud.
With this report, you can:
- Identify pages that contain Mosaic macros
- Understand potential compatibility risks
- Take action before migration to avoid broken or missing content in Cloud
This feature ensures you have the visibility you need to plan a smoother, more reliable migration experience.
9.0.1
4th September 2025
Security Update
CVE-2025-53864 - Third-Party Library Vulnerability Update
A vulnerability was discovered within a third party library that is used by Mosaic.
CVE : https://nvd.nist.gov/vuln/detail/CVE-2025-53864
Library Name: nimbus-jose-jwt
Affected Library Version: v9.37.3
Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.
Action Taken
To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.
Recommendations
- We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
- More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-53864
CVE-2025-48924 - Third-Party Library Vulnerability Update
A vulnerability was discovered within a third party library that is used by Mosaic.
CVE : https://nvd.nist.gov/vuln/detail/CVE-2025-48924
Library Name: commons-lang
Affected Library Version: v2.6 & v-3.12.0
Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.
Action Taken
To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.
Recommendations
- We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
- More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-48924
Third-Party Library Vulnerability Update
A vulnerability was discovered within a third party library that is used by Mosaic.
Library Name: image-size
Affected Library Version: >= 1.1.0, < 1.2.1 and >= 2.0.0, < 2.0.2
Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.
Action Taken
To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.
Recommendations
We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
8.0.14
Security Update
CVE-2025-53864 - Third-Party Library Vulnerability Update
A vulnerability was discovered within a third party library that is used by Mosaic.
CVE : https://nvd.nist.gov/vuln/detail/CVE-2025-53864
Library Name: nimbus-jose-jwt
Affected Library Version: v9.37.3
Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.
Action Taken
To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.
Recommendations
- We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
- More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-53864
CVE-2025-48924 - Third-Party Library Vulnerability Update
A vulnerability was discovered within a third party library that is used by Mosaic.
CVE : https://nvd.nist.gov/vuln/detail/CVE-2025-48924
Library Name: commons-lang
Affected Library Version: v2.6 & v-3.12.0
Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.
Action Taken
To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.
Recommendations
- We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
- More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-48924
Third-Party Library Vulnerability Update
A vulnerability was discovered within a third party library that is used by Mosaic.
Library Name: image-size
Affected Library Version: >= 1.1.0, < 1.2.1 and >= 2.0.0, < 2.0.2
Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.
Action Taken
To minimize the risk, we have updated the version of the library that Mosaic uses. We have selected a version that has no known vulnerabilities.
Recommendations
We always recommend updating to the latest version of Mosaic to ensure you are running the latest and most secure software.
8.0.13
This version is only compatible with Confluence 8 and 9.
25th August 2025
Fixes
- In a small number of cases it was possible to bypass the URL allowlist. This has now been resolved.
9.0.0
11th August 2025
Updates
- Compatibility updates for Confluence 10.
Fixes
In a small number of cases it was possible to bypass the URL allowlist. This has now been resolved.
8.0.12
31st July 2025
Security Update
CVE-2025-48734 - Third-Party Library Vulnerability Update
A vulnerability was discovered within a third party library that is used by Mosaic for Confluence.
CVE :https://nvd.nist.gov/vuln/detail/CVE-2025-48734
Library Name: Apache commons-beanutils
Affected Library Version: v1.9.4
Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.
Action Taken
To minimize the risk, we have updated the version of the library that Mosaic for Confluence uses. We have selected a version that has no known vulnerabilities.
Recommendations
- We always recommend updating to the latest version of Mosaic for Confluence to ensure you are running the latest and most secure software.
- More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2025-48734.
CVE-2025-5878 - Third-Party Library Vulnerability Update
A vulnerability was discovered within a third party library that is used by Mosaic for Confluence.
CVE :https://nvd.nist.gov/vuln/detail/CVE-2023-5878
Library Name: ESAPI
Affected Library Version: v2.6.0
Our analysis confirms that Mosaic for Confluence does not use the affected components of the library, so is not vulnerable to the reported issue.
Action Taken
To minimize the risk, we have updated the version of the library that Mosaic for Confluence uses. We have selected a version that has no known vulnerabilities.
Recommendations
- We always recommend updating to the latest version of Mosaic for Confluence to ensure you are running the latest and most secure software.
- More information about the vulnerability can be found here https://nvd.nist.gov/vuln/detail/CVE-2023-5878.
8.0.11
12th June 2025
Fixes
- Fixed an issue where the Search Box macro was occasionally leading to performance issues.
8.0.10
26th March 2025
Fixes
- The iframe Macro no longer shows a system error when opened.
8.0.9
5th March 2025
Fixes
- Made a security fix.
- Help links from all macros now take you to the correct page in the documentation.
- The iframe macro now works as expected in all version of Confluence 9.
- Tabs with lazy loading enabled now correctly load their content.
- The Clickable macro now displays and works as expected.
- Users can now create multiple pages using the Blog template without issue.
8.0.8
30th January 2025
Updates
Updates
We're excited to announce that Content Formatting Macros is starting the new year with a new name - Mosaic for Confluence. We are very proud of how much Content Formatting Macros has grown and changed over the years. This new name represents the latest phase in our journey as we continue to strive to give our users the best tools to get the most out of Confluence.
Fixes
Made a security update.
8.0.7
22nd January 2025
Fixes
- The CSS Style sheet macro no longer causes a html comment to appear when it is added to a page.
- The link to manage our app from the Manage App screen no longer gives a 404 error.
- Fixed issues where tables did not display as expected when combined with tabs or other rich macros.
8.0.6
16th December 2024
Urgent Update
Unfortunately an issue was present in versions 8.0.3, 8.0.4, and 8.0.5. This issue led to the loss of content inside HTML Comment macros. If you are using one of these versions we recommend updating to version 8.0.6 as soon as possible.To avoid loss of content inside these macros we recommend taking the following steps.
- Copy content from any HTML Comment macros in your instance.
- Upgrade to version 8.0.6.
- If required, copy missing content into HTML Comment macros.
Updates
- Made a number of security updates.
Fixes
- HTML Comments now show as expected.
- Fixed an issue where CSS Stylesheet was changing the color of buttons from 3rd party apps.
- Table headers now show as expected.
- The first rows of tables now respect the type of cell used.
8.0.2
29th October 2024
Fixes
- CSS styles are no longer incorrectly applied to buttons within forms.
- Made a security update.
8.0.1
7th October 2024
Fixes
- Fixed an issue that was causing data inside tables in tabs to be formatted as buttons.
- Fixed an issue where the Rollover macro was not correctly redirecting to some links.
-
The following content is now correctly displayed within the Alert macro
- Tables
- Buttons
- User Tags
- Links
- Profile Picture macro content
- Fixed an issue where HTML table was not displaying correctly
- Resolved an issues where CSS Style Sheet did not work as expected when used with a third party app.
8.0.0
5th August 2024
Updates
- Compatibility updates for Confluence 9.
7.2.7
30th May 2024
Fixes
- Made a security update.
- Fixed an issue where formatting inside the Alert macro was not working as expected.
7.2.6
15th May 2024
Fixes
- Fixed an issue where the Rollover macro was not displaying images.
- Made a security update.
We recommend updating to this version as soon as possible.
6.6.5
15th May 2024
Fixes
- Fixed an issue where the Rollover macro was not displaying images.
7.2.5
2nd April 2024
Updates
- We have made several updates to the way our app works in preparation for the release of Confluence 9.
Fixes
- Minor security improvements have been made by updating 3rd party software to versions with no known vulnerabilities.
- A number of 3rd party libraries have been identified to have vulnerabilities. While the vulnerable components of these libraries are not used, the libraries have been patched to a version with no identified vulnerabilities to prevent accidental use of the components in the future.
6.6.4
2nd April 2024
Fixes
- Minor security improvements have been made by updating 3rd party software to versions with no known vulnerabilities.
- A number of 3rd party libraries have been identified to have vulnerabilities. While the vulnerable components of these libraries are not used, the libraries have been patched to a version with no identified vulnerabilities to prevent accidental use of the components in the future.
7.2.4
20th November 2023
Fixes
- Minor security improvements have been made by updating 3rd party software to versions with no known vulnerabilities.
- During an audit of 3rd party software used by Content Formatting Macros for Confluence, some were found to have vulnerabilities. Investigating the concerns showed that Content Formatting Macros used no vulnerable components for Confluence, regardless we have updated the version used.
6.6.3
Fixes
- Minor security improvements have been made by updating 3rd party software to versions with no known vulnerabilities.
- During an audit of 3rd party software used by Content Formatting Macros for Confluence, some were found to have vulnerabilities. Investigating the concerns showed that Content Formatting Macros used no vulnerable components for Confluence, regardless we have updated the version used.
7.2.3
4th August 2023
Re-release of 7.2.2.
6.6.1
Bug Fixes
Fixed a bug where the CSS style sheet macro was changing the appearance of buttons.
7.2.2
15th June 2023
Fixes
Compatability updates for Confluence 8.3
7.2.1
26th May 2023
Fixes
- Compatability updates for Confluence 8.3
- Fix for a bug affecting the footnotes macro
7.2.0
3rd May 2023
Update
In-app rebranding changes
7.1.1
5th April 2023
Update
Rebranding changes
Your favorite macros have a new look.
We're excited to tell you that Content Formatting Macros for Confluence is now part of Kolekti, a new brand under The Adaptavist Group.
We've updated our apps and macros with a fresh new color - we hope you like the new look.
The app (and our team!) are still the same. We'll keep working hard to give you market-leading tools and support you can rely on.
7.0.2
21st March 2023
Update
Compatibility with Confluence 8.1
There is a minor issue with rendering the table head(th) macro due to a change that Atlassian introduced:
- The issue affects the styling capabilities of the macro, so the table content may present appear different than expected in publish mode.
- Data won't be lost; content and configuration will be accessible as usual in edit mode.
We have escalated the issue with the highest priority with Atlassian and hope to have an update shortly. In addition, our team is working to achieve full compatibility. Once resolved, we will release a new version of the app.
7.0.1
3rd February 2023
Fixes
Fix to ensure correct display of text in the Button macro
7.0.0
19th January 2023
Update
Compatibility with Confluence 8
This update is only compatible with Confluence 8. It is not backward compatible.
6.6.0
26th October 2022
Fixes
Security update to address vulnerabilities
Fix made to tabs to allow them to be viewed anonymously when lazy loading is enabled.
6.5.3
10th October 2022
Fixes
Security update to address vulnerabilities
Update
In response to a request, Improvements have been made to log output from the CSS Stylesheet Macro. This will allow Admins to find the location of CSS errors within stylesheets more easily.
6.5.1
9th August 2022
Fixes
Security update to address vulnerabilities
6.5.0
27th July 2022
Fixes
Security update to address Atlassian Vulnerability
6.4.26
13th June 2022
Updates
- Improvements made to the copy in the macro editors to improve the user experience.
- Search information update for macros to make it easier to find the macro you need.
- Colgroup Marco deprecated.
6.4.25
4th April 2022
Fixes
- Correcting description for the Search Box Macro
- Security Patch: Fixed XSS vulnerabilities in Rollover and Progress Bar Macros
6.4.23
16th February 2022
Fixes
- Minor Bug Fix
- Updating MathJax to the latest version
6.4.21
26th January 2022
Fixes
- Fixed an issue with Tooltip in Confluence 7.12
- Fixed a minor bug in Footnote's rendering of backslashes
- Security Patch: Fixed XSS vulnerabilities
6.4.20
25 November 2021
Fixes
- Corrected error on colgroup with CSS
6.4.19
12 October 2021
Fixes
- Minor Bug Fix
6.4.18
6 October 2021
Fixes
- Fixed a security vulnerability with the Rollover Macro
6.4.17
23 September 2021
Fixes
- Updated in-app links for new documentation site
6.4.16
3 August 2021
Analytics Update
Improved analytics to help determine areas to improve value to the customer
6.4.15
8 July 2021
Fixes
- Fixed Latex issue on instance hosted on AWS
- Made Bibtex display order the same as page order
- Fixed Footnotes not showing backslashes
6.4.14
23 June 2021
Fixes
- Fixed menu bar not sticking
- Fixed issue with links in footnotes
6.4.13
13 May 2021
Updates
- Compatibility with Confluence 7.12.0
Fixes
- Resolved Dialog macro issue to make it compatible with AUI 9
- Footnote macro tooltip now shows on hover for Confluence 7.12.0
6.4.11
20 April 2021
Analytics Update
Improved analytics to help determine areas to improve value to the customer
Fixes
- Updated in-app links for new documentation site
6.4.10
12 April 2021
Fixes
- Updated in-app links for new documentation site
6.4.9
23 March 2021
Analytics Update
- Improved analytics to help determine areas to improve value to the customer
6.4.8
12 March 2021
What's new
- Analytics Update: Updated the analytics architecture to improve reporting
6.4.7
17 Nov 2020
Fixes
-
Security patch: Fixed a security vulnerability and other minor fixes
We recommend upgrading to this version or later versions.
6.4.6
13 Oct 2020
Compatible with Confluence Server and Confluence Data Center 6.13.0-7.9.3
Fixes
-
Security patch: Replaced a third-party library that contained a vulnerability
We recommend upgrading to this version or later versions.
6.4.5
15 April 2020
Compatible with Confluence Data Center 6.12.0-7.7.4
What's new
- Data Center Read-only Mode compatibility
6.4.4
18 Feb 2020
Fixes
- Fixed an issue where logging was being blocked in versions 6.3.2-6.3.3.
6.4.3
09 Dec 2019
Fixes
- Fixed an issue where relative URLs were not being supported by the Confluence whitelist for Style Sheet macro (CONTENTF-1160).
- Made improvements to our in-product analytics.
6.4.2
26 Nov 2019
Fixes
- Fixed an issue with certain macros and Tomcat configuration (CONTENTF-1131).
6.4.1
21 Nov 2019
Fixes
- Patched a vulnerability that was affecting the Style Sheet macro. This vulnerability is classed as high according to Atlassian's security severity levels. More information can be found in our public ticket, (CONTENTF-1150). We recommend customers update to version 6.4.1 of Content Formatting Macros for Confluence as soon as possible. If you are unable to upgrade at this time we recommend that you disable the Style Sheet macro from the universal plug-in manager.
6.4.0
02 Oct 2019
What's new
- Introduced a new system of gathering anonymous analytics to gain insight into how it is used with the aim of improving user experience. For more information, please see the Analytics topic in our documentation.
6.3.5
17 Sep 2019
Fixes
- Fixed a security vulnerability (CONTENTF-1107)
- Vulnerability is classified as critical, according to Atlassian's security severity levels, and affects only the LaTeX Formatting macro and Restful Table macro
6.3.4
10 Jul 2019
Fixes
- Fixed an issue when Iframe macro without a URL caused import tool to hang at 0% ( CONTENTF-1036)
- Fixed documentation links on the configuration menu for Alert, Colgroup Tag, and Tooltip macros
6.3.3
06 Jun 2019
What's new
Reworked Footnotes Macro to make exporting content with footnotes more usable in MS Word and PDF (CONTENTF-306)
Fixes
Fixed an issue where line breaks were being ignored with the Highlight Macro (CONTENTF-87)
6.3.2
13 May 2019
Fixes
- Increased the URL limit to 2000 characters in the Iframe Configuration feature, which fixed an issue where the URL Import Tool would not complete if it encountered a long URL. ( CONTENTF-316)
- Fixed an issue with version 6.3.1 of Content Formatting where the LaTeX macro would not render ( CONTENTF-317)
6.3.1
02 May 2019
We strongly recommend customers update to version 6.3.1 of Content Formatting as soon as possible. If customers are unable to upgrade at this time we recommend that they disable the Iframe macro module in the Content Formatting for Confluence section of the Confluence app menu.
- Added Iframe Macro Configuration feature to resolve security vulnerability
- Will automatically add the sandbox attribute to all Iframes and give Confluence Administrators the ability to allow, sandbox, or deny iframes.
- Fixed a security vulnerability ( CONTENTF-223)
- The vulnerability is classified as medium according to Atlassian's security severity levels and affects only the Iframe macro
6.2.9
31 Jan 2019
What's new
- Updated 3rd party libraries containing a security patch.
- Made Content Formatting compatible with Confluence version 6.14.
- Added a new getting started page for Confluence Admins.
6.2.8
23 Jan 2019
What's new
Enabled mobile compatibility
Fixes
Fixed a problem where the Button Hyperlink macro causes an error when target page title includes '/' (CONTENTF-130)
Fixed a problem where users weren't able to create an AUI Button that had a file link to a network driver as the target URL (CONTENTF-142)
6.2.6
25 Oct 2018
Fixes
Fixed minor bugs and compatibility with Confluence 6.12
6.2.5
03 Oct 2018
What's new
- Upgraded Jackson Databind library to patch CVE-2018-7489, which is a recommended upgrade for all Content Formatting for Confluence users.
6.2.4
03 Sep 2018
What's new
Released Confluence Data Center
Fixes
Fixed bugs causing issues with horizontal navigation
Fixed budges causing issues with tab jumping
6.2.3
31 Aug 2018
Fixes
Fixed minor bugs
6.2.2
What's new
Made Content Formatting compatible with Confluence 6.11.x
Fixes
Made macro improvements
Fixed minor bugs
6.2.1
27 Jul 2018
Fixes
Fixed minor bugs
6.2.0
09 Jul 2018
What's new
Made Content Formatting compatible with Confluence 6.10.x
Fixes
Fixed minor bugs
6.1.5
15 Jun 2018
Fixes
Fixed minor bugs
6.1.4
25 May 2018
What's new
Made Content Formatting compatible with Confluence 6.9.x
Fixes
Fixed minor bugs
6.1.3
03 Apr 2018
What's new
- Made Content Formatting compatible with Confluence 6.8.x
6.1.2
05 Mar 2018
Fixes
Fixed minor bugs
6.1.1
01 Mar 2018
Fixes
Fixes
Fixed minor bugs
6.1.0
05 Feb 2018
What's new
Added Content Formatting Templates feature
6.0.12
13 Dec 2017
What's new
- Made Content Formatting compatible with Confluence 6.6.x
6.0.11
14 Nov 2017
Fixes
Fixed minor bugs
6.0.10
09 Nov 2017
What's new
Added footnotes reset counter option
Fixes
Fixed minor bugs
6.0.9
01 Nov 2017
What's new
- Made Content Formatting compatible with Confluence 6.5.0
6.0.8
06 Sep 2017
Fixes
Fixed minor bugs
6.0.7
25 Aug 2017
This version contains two security vulnerabilities, we recommend you update to version 6.3.1 or later https://productsupport.adaptavist.com/browse/CONTENTF-105https://productsupport.adaptavist.com/browse/CONTENTF-223
Fixes
Fixed minor bugs
6.0.6
Fixes
Fixed minor bugs
6.0.5
Fixes
Fixed minor bugs
6.0.4
Fixes
Fixed minor bugs
6.0.3
Fixes
Fixed minor bugs
6.0.2
12 Jul 2017
What's new
Made Content Formatting compatible with Confluence 6.3.x
Fixes
Fixed minor bugs
6.0.1
12 Jun 2017
Fixes
Fixed minor bugs
6.0.0
23 May 2017
What's new
Added three new macros
Added ability to reference content using footnotes
Fixes
Improved Tabs Macro