VendorsJetBrainsintellij_ideaany version
Vulnerabilities

JetBrains IntelliJ IDEA any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

74CVEs
CVE-2022-47895
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
Published 2022-12-22 · Modified
7.5EPSS 0.002
CVE-2025-57727
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
Published 2025-08-20 · Analyzed
7.5EPSS 0.002
CVE-2020-7904
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
Published 2020-01-30 · Modified
7.4EPSS 0.014
CVE-2025-57729
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
Published 2025-08-20 · Analyzed
7.3EPSS 0.001
CVE-2022-29818
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
Published 2022-04-28 · Modified
7.1EPSS 0.002
CVE-2022-29815
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
Published 2022-04-28 · Modified
6.9EPSS 0.002
CVE-2022-29813
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
Published 2022-04-28 · Modified
6.9EPSS 0.002
CVE-2025-57728
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
Published 2025-08-20 · Analyzed
6.5EPSS 0.002
CVE-2026-75054
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
Published 2026-08-17 · Analyzed
6.3EPSS 0.002
CVE-2022-46826
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
Published 2022-12-08 · Modified
6.2EPSS 0.002
CVE-2026-75057
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
Published 2026-08-17 · Analyzed
6.2EPSS 0.002
CVE-2024-46970
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
Published 2024-09-16 · Analyzed
6.1EPSS 0.004
CVE-2022-29817
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
Published 2022-04-28 · Modified
6.1EPSS 0.004
CVE-2024-24941
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
Published 2024-02-06 · Modified
6.1EPSS 0.003
CVE-2026-64810
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
Published 2026-07-23 · Analyzed
6.1EPSS 0.003
CVE-2019-14954
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
Published 2019-10-01 · Modified
5.9EPSS 0.007
CVE-2022-46827
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
Published 2022-12-08 · Modified
5.5EPSS 0.002
CVE-2026-75058
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
Published 2026-08-17 · Analyzed
5.5EPSS 0.002
CVE-2026-75055
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
Published 2026-08-17 · Analyzed
5.5EPSS 0.002
CVE-2026-75053
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
Published 2026-08-17 · Analyzed
5.4EPSS 0.002
CVE-2025-68269
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
Published 2025-12-16 · Analyzed
5.4EPSS 0.001
CVE-2020-27622
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
Published 2020-11-16 · Modified
5.3EPSS 0.013
CVE-2021-25756
In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.
Published 2021-02-03 · Modified
5.3EPSS 0.013
CVE-2019-18361
JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.
Published 2019-10-31 · Modified
5.3EPSS 0.004
CVE-2025-57730
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
Published 2025-08-20 · Analyzed
5.2EPSS 0.004
CVE-2026-75052
In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects
Published 2026-08-17 · Analyzed
4.4EPSS 0.002
CVE-2024-24940
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
Published 2024-02-06 · Modified
4.3EPSS 0.003
CVE-2022-46825
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
Published 2022-12-08 · Modified
4.0EPSS 0.001
CVE-2022-37010
In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed
Published 2022-07-28 · Modified
3.6EPSS 0.002
CVE-2025-32054
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
Published 2025-04-03 · Analyzed
3.3EPSS 0.004
CVE-2023-38069
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases
Published 2023-07-12 · Modified
3.3EPSS 0.002
CVE-2026-49383
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
Published 2026-05-29 · Analyzed
3.3EPSS 0.001
CVE-2022-29816
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
Published 2022-04-28 · Modified
3.2EPSS 0.003
CVE-2022-29812
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
Published 2022-04-28 · Modified
2.3EPSS 0.002
← Prev2 / 2