VendorsJetBrainsteamcityall versions
Vulnerabilities

JetBrains TeamCity

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

275CVEs
CVE-2023-34226
In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible
Published 2023-05-31 · Modified
6.1EPSS 0.010
CVE-2023-38066
In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads
Published 2023-07-12 · Modified
6.1EPSS 0.010
CVE-2023-39175
In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible
Published 2023-07-25 · Modified
6.1EPSS 0.010
CVE-2019-12844
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
Published 2019-07-03 · Modified
6.1EPSS 0.008
CVE-2019-12842
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
Published 2019-07-03 · Modified
6.1EPSS 0.008
CVE-2019-12843
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
Published 2019-07-03 · Modified
6.1EPSS 0.008
CVE-2019-15037
An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.
Published 2019-10-02 · Modified
6.1EPSS 0.008
CVE-2020-15830
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
Published 2020-08-08 · Modified
6.1EPSS 0.008
CVE-2021-31904
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
Published 2021-05-11 · Modified
6.1EPSS 0.007
CVE-2021-31911
In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.
Published 2021-05-11 · Modified
6.1EPSS 0.007
CVE-2020-27627
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
Published 2020-11-16 · Modified
6.1EPSS 0.007
CVE-2020-7911
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.
Published 2020-01-30 · Modified
6.1EPSS 0.006
CVE-2020-15831
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
Published 2020-08-08 · Modified
6.1EPSS 0.006
CVE-2021-25773
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
Published 2021-02-03 · Modified
6.1EPSS 0.006
CVE-2021-37542
In JetBrains TeamCity before 2020.2.3, XSS was possible.
Published 2021-08-06 · Modified
6.1EPSS 0.006
CVE-2022-24330
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
Published 2022-02-25 · Modified
6.1EPSS 0.006
CVE-2021-43197
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
Published 2021-11-09 · Modified
6.1EPSS 0.006
CVE-2022-24338
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
Published 2022-02-25 · Modified
6.1EPSS 0.006
CVE-2022-25261
JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
Published 2022-02-25 · Modified
6.1EPSS 0.006
CVE-2024-31135
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
Published 2024-03-28 · Modified
6.1EPSS 0.005
CVE-2022-29929
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
Published 2022-05-12 · Modified
6.1EPSS 0.005
CVE-2025-26493
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
Published 2025-02-11 · Analyzed
6.1EPSS 0.004
CVE-2022-48344
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
Published 2023-02-23 · Modified
6.1EPSS 0.004
CVE-2023-41250
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
Published 2023-08-25 · Modified
6.1EPSS 0.004
CVE-2024-43809
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
Published 2024-08-16 · Analyzed
6.1EPSS 0.003
CVE-2026-49375
In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
Published 2026-05-29 · Analyzed
6.1EPSS 0.003
CVE-2026-28194
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
Published 2026-02-25 · Analyzed
6.1EPSS 0.003
CVE-2024-35300
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
Published 2024-05-16 · Analyzed
6.1EPSS 0.003
CVE-2024-36366
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
Published 2024-05-29 · Analyzed
6.1EPSS 0.003
CVE-2024-35302
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
Published 2024-05-16 · Analyzed
6.1EPSS 0.003
CVE-2024-36372
In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
Published 2024-05-29 · Analyzed
6.1EPSS 0.003
CVE-2024-36367
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
Published 2024-05-29 · Analyzed
6.1EPSS 0.003
CVE-2025-47854
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
Published 2025-05-20 · Analyzed
6.1EPSS 0.003
CVE-2026-49380
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
Published 2026-05-29 · Analyzed
6.1EPSS 0.002
CVE-2025-68268
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
Published 2025-12-16 · Analyzed
6.1EPSS 0.002
CVE-2025-68166
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
Published 2025-12-16 · Analyzed
6.1EPSS 0.002
CVE-2024-28174
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
Published 2024-03-06 · Analyzed
5.8EPSS 0.003
CVE-2025-59456
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
Published 2025-09-17 · Analyzed
5.5EPSS 0.130
CVE-2021-25775
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
Published 2021-02-03 · Modified
5.5EPSS 0.006
CVE-2024-56354
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
Published 2024-12-20 · Analyzed
5.5EPSS 0.003
← Prev4 / 7Next →