VendorsJetBrainsintellij_ideaall versions
Vulnerabilities

JetBrains IntelliJ IDEA

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

76CVEs
CVE-2026-64813
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Published 2026-07-23 · Analyzed
10.0EPSS 0.005
CVE-2026-64812
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
Published 2026-07-23 · Analyzed
10.0EPSS 0.005
CVE-2019-9186
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost interface). This issue has been fixed in the following versions: 2019.1, 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.
Published 2019-07-03 · Modified
9.8EPSS 0.045
CVE-2019-10104
In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.
Published 2019-07-03 · Modified
9.8EPSS 0.038
CVE-2020-11690
In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
Published 2020-04-22 · Modified
9.8EPSS 0.023
CVE-2019-9823
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8, 2018.1.8.
Published 2019-07-03 · Modified
9.8EPSS 0.016
CVE-2019-9873
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.
Published 2019-07-03 · Modified
9.8EPSS 0.016
CVE-2021-45977
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.
Published 2022-02-25 · Modified
9.8EPSS 0.011
CVE-2026-59792
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
Published 2026-07-10 · Analyzed
9.8EPSS 0.006
CVE-2026-64815
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
Published 2026-07-23 · Analyzed
9.8EPSS 0.005
CVE-2023-51655
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
Published 2023-12-21 · Modified
9.8EPSS 0.003
CVE-2024-37051
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4
Published 2024-06-10 · Modified
9.3EPSS 0.038
CVE-2026-49367
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
Published 2026-05-29 · Analyzed
8.8EPSS 0.005
CVE-2022-48432
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
Published 2023-03-29 · Modified
8.8EPSS 0.002
CVE-2026-64814
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Published 2026-07-23 · Analyzed
8.6EPSS 0.004
CVE-2022-28651
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
Published 2022-04-05 · Modified
8.4EPSS 0.003
CVE-2019-9872
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and configured to synchronize IDE settings using a public repository, these credentials were published to this repository. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.
Published 2019-07-03 · Modified
8.1EPSS 0.012
CVE-2017-8316
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
Published 2018-08-03 · Modified
7.8EPSS 0.023
CVE-2021-25758
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
Published 2021-02-03 · Modified
7.8EPSS 0.010
CVE-2026-49366
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
Published 2026-05-29 · Analyzed
7.8EPSS 0.007
CVE-2021-29263
In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.
Published 2021-05-11 · Modified
7.8EPSS 0.005
CVE-2022-24346
In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.
Published 2022-02-25 · Modified
7.8EPSS 0.004
CVE-2022-24345
In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.
Published 2022-02-25 · Modified
7.8EPSS 0.004
CVE-2023-39261
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions
Published 2023-07-26 · Modified
7.8EPSS 0.003
CVE-2022-46828
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
Published 2022-12-08 · Modified
7.8EPSS 0.003
CVE-2022-40978
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
Published 2022-09-19 · Modified
7.8EPSS 0.003
CVE-2022-47896
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
Published 2022-12-22 · Modified
7.8EPSS 0.003
CVE-2022-37009
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
Published 2022-07-28 · Modified
7.8EPSS 0.003
CVE-2026-75056
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
Published 2026-08-17 · Analyzed
7.8EPSS 0.002
CVE-2026-64811
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
Published 2026-07-23 · Analyzed
7.8EPSS 0.002
CVE-2026-49382
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
Published 2026-05-29 · Analyzed
7.8EPSS 0.002
CVE-2022-46824
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
Published 2022-12-08 · Modified
7.8EPSS 0.002
CVE-2022-48431
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
Published 2023-03-29 · Modified
7.8EPSS 0.001
CVE-2022-29814
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
Published 2022-04-28 · Modified
7.7EPSS 0.002
CVE-2022-29819
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
Published 2022-04-28 · Modified
7.7EPSS 0.002
CVE-2021-30504
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
Published 2021-05-11 · Modified
7.5EPSS 0.023
CVE-2020-7914
In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.
Published 2020-01-31 · Modified
7.5EPSS 0.019
CVE-2020-7905
Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.
Published 2020-01-30 · Modified
7.5EPSS 0.012
CVE-2021-30006
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
Published 2021-05-11 · Modified
7.5EPSS 0.011
CVE-2022-48433
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
Published 2023-03-29 · Modified
7.5EPSS 0.006
1 / 2Next →