VendorsJetBrainsteamcityany version
Vulnerabilities

JetBrains TeamCity any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

265CVEs
CVE-2020-15830
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
Published 2020-08-08 · Modified
6.1EPSS 0.008
CVE-2021-31904
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
Published 2021-05-11 · Modified
6.1EPSS 0.007
CVE-2021-31911
In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.
Published 2021-05-11 · Modified
6.1EPSS 0.007
CVE-2020-27627
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
Published 2020-11-16 · Modified
6.1EPSS 0.007
CVE-2020-7911
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.
Published 2020-01-30 · Modified
6.1EPSS 0.006
CVE-2020-15831
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
Published 2020-08-08 · Modified
6.1EPSS 0.006
CVE-2021-25773
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
Published 2021-02-03 · Modified
6.1EPSS 0.006
CVE-2021-37542
In JetBrains TeamCity before 2020.2.3, XSS was possible.
Published 2021-08-06 · Modified
6.1EPSS 0.006
CVE-2022-24330
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
Published 2022-02-25 · Modified
6.1EPSS 0.006
CVE-2021-43197
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
Published 2021-11-09 · Modified
6.1EPSS 0.006
CVE-2022-24338
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
Published 2022-02-25 · Modified
6.1EPSS 0.006
CVE-2022-25261
JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
Published 2022-02-25 · Modified
6.1EPSS 0.006
CVE-2024-31135
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
Published 2024-03-28 · Modified
6.1EPSS 0.005
CVE-2022-29929
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
Published 2022-05-12 · Modified
6.1EPSS 0.005
CVE-2025-26493
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
Published 2025-02-11 · Analyzed
6.1EPSS 0.004
CVE-2022-48344
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
Published 2023-02-23 · Modified
6.1EPSS 0.004
CVE-2023-41250
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
Published 2023-08-25 · Modified
6.1EPSS 0.004
CVE-2024-43809
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
Published 2024-08-16 · Analyzed
6.1EPSS 0.003
CVE-2026-49375
In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
Published 2026-05-29 · Analyzed
6.1EPSS 0.003
CVE-2026-28194
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
Published 2026-02-25 · Analyzed
6.1EPSS 0.003
CVE-2024-36366
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
Published 2024-05-29 · Analyzed
6.1EPSS 0.003
CVE-2024-35302
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
Published 2024-05-16 · Analyzed
6.1EPSS 0.003
CVE-2024-36372
In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
Published 2024-05-29 · Analyzed
6.1EPSS 0.003
CVE-2024-36367
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
Published 2024-05-29 · Analyzed
6.1EPSS 0.003
CVE-2025-47854
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
Published 2025-05-20 · Analyzed
6.1EPSS 0.003
CVE-2026-49380
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
Published 2026-05-29 · Analyzed
6.1EPSS 0.002
CVE-2025-68268
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
Published 2025-12-16 · Analyzed
6.1EPSS 0.002
CVE-2025-68166
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
Published 2025-12-16 · Analyzed
6.1EPSS 0.002
CVE-2024-28174
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
Published 2024-03-06 · Analyzed
5.8EPSS 0.003
CVE-2025-59456
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
Published 2025-09-17 · Analyzed
5.5EPSS 0.130
CVE-2021-25775
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
Published 2021-02-03 · Modified
5.5EPSS 0.006
CVE-2024-56354
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
Published 2024-12-20 · Analyzed
5.5EPSS 0.003
CVE-2025-57733
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
Published 2025-08-20 · Analyzed
5.5EPSS 0.003
CVE-2024-35301
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
Published 2024-05-16 · Analyzed
5.5EPSS 0.003
CVE-2025-54538
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
Published 2025-07-28 · Analyzed
5.5EPSS 0.003
CVE-2025-54537
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
Published 2025-07-28 · Analyzed
5.5EPSS 0.003
CVE-2024-31138
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
Published 2024-03-28 · Modified
5.4EPSS 0.745
CVE-2022-48428
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
Published 2023-03-27 · Modified
5.4EPSS 0.680
CVE-2023-34220
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
Published 2023-05-31 · Modified
5.4EPSS 0.612
CVE-2023-34225
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
Published 2023-05-31 · Modified
5.4EPSS 0.607
← Prev4 / 7Next →