Comparison Overview
ClickUp

ClickUp
350 Tenth Ave, San Diego, 92101, US
Last Update: 29/04/2026
ClickUp is the world’s first Converged AI Workspace, replacing all software and AI with a single place for humans and AI agents to work together. ClickUp eliminates all forms of work sprawl, creates 100% context, and drives unprecedented productivity, collaboration, and...

Atlassian
Level 6/341 George St, Sydney, 2000, AU
Last Update: 10/08/2026
Atlassian powers the collaboration that helps teams accomplish what would otherwise be impossible alone. From space missions and motor racing to bugs in code and IT requests, no task is too large or too small with the right team, the right tools, and the right practice...
Compliance Ranges Comparison

ClickUp







Atlassian






Benchmark & Cyber Underwriting Signals
Incidents vs Software Development Industry Avg (This Year)
ClickUp has 5.66% fewer incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Software Development Industry Avg (This Year)
Atlassian has 288.35% more incidents than the average of all companies with at least one recorded incident.
Incident History - ClickUp (X = Date, Y = Severity)
ClickUp cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Atlassian (X = Date, Y = Severity)
Atlassian cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

ClickUp

Atlassian
FAQ
Latest Global CVEs
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The attack may be initiated remotely. This vulnerability is distinct from CVE-2026-34159 (GHSA-j8rj-fmpv-wcxw, PR #20908), which only added a buffer==nullptr rejection in create_node() and does not validate op or op_params. The reported GitHub issue was closed automatically due to inactivity.
A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the argument Next leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 5d8515842fd1ab2c3a9f2dde9ffca907aa334ea9. Upgrading the affected component is recommended.
- https://github.com/CTFd/CTFd/
- https://github.com/CTFd/CTFd/commit/5d8515842fd1ab2c3a9f2dde9ffca907aa334ea9
- https://github.com/CTFd/CTFd/pull/3026
- https://github.com/CTFd/CTFd/releases/tag/3.8.4
- https://mblunt.dev/writeups/ctfd-open-redirect/
- https://vuldb.com/cve/CVE-2026-78145
- https://vuldb.com/submit/882469
- https://vuldb.com/vuln/394533
- https://vuldb.com/vuln/394533/cti
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management Module. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used.
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The manipulation of the argument resident_id results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used.