JetBrains / YouTrack
145 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-103497 | In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration | MEDIUM | 5.5 | Oct 1, 2026 |
| CVE-2026-103496 | In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications | MEDIUM | 5.4 | Oct 1, 2026 |
| CVE-2026-103495 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs | MEDIUM | 4.3 | Oct 1, 2026 |
| CVE-2026-103494 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes | MEDIUM | 6.6 | Oct 1, 2026 |
| CVE-2026-103493 | In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible | HIGH | 8.1 | Oct 1, 2026 |
| CVE-2026-103492 | In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments | MEDIUM | 6.5 | Oct 1, 2026 |
| CVE-2026-103491 | In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues | MEDIUM | 6.5 | Oct 1, 2026 |
| CVE-2026-103490 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links | HIGH | 7.2 | Oct 1, 2026 |
| CVE-2026-103489 | In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible | LOW | 2.0 | Oct 1, 2026 |
| CVE-2026-103488 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues | HIGH | 7.1 | Oct 1, 2026 |
| CVE-2026-100280 | In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible | MEDIUM | 4.3 | Sep 30, 2026 |
| CVE-2026-100279 | In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials | MEDIUM | 6.5 | Sep 30, 2026 |
| CVE-2026-100278 | In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments | MEDIUM | 4.9 | Sep 30, 2026 |
| CVE-2026-100277 | In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature | CRITICAL | 9.8 | Sep 30, 2026 |
| CVE-2026-100276 | In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action | HIGH | 7.5 | Sep 30, 2026 |
| CVE-2026-100275 | In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible | MEDIUM | 6.9 | Sep 30, 2026 |
| CVE-2026-100274 | In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template | MEDIUM | 6.5 | Sep 30, 2026 |
| CVE-2026-100273 | In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution | CRITICAL | 9.8 | Sep 30, 2026 |
| CVE-2026-100272 | In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues | MEDIUM | 4.9 | Sep 30, 2026 |
| CVE-2026-100271 | In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects | LOW | 2.7 | Sep 30, 2026 |
| CVE-2026-100270 | In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations | LOW | 3.3 | Sep 30, 2026 |
| CVE-2026-100264 | In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | LOW | 2.7 | Sep 30, 2026 |
| CVE-2026-100263 | In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | MEDIUM | 6.1 | Sep 30, 2026 |
| CVE-2026-100262 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | HIGH | 7.6 | Sep 30, 2026 |
| CVE-2026-100261 | In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | MEDIUM | 5.4 | Sep 30, 2026 |
Showing 1 to 25 of 145 CVEs