VendorsJetBrainsteamcityall versions
Vulnerabilities

JetBrains TeamCity

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

275CVEs
CVE-2025-57733
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
Published 2025-08-20 · Analyzed
5.5EPSS 0.003
CVE-2024-35301
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
Published 2024-05-16 · Analyzed
5.5EPSS 0.003
CVE-2025-54538
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
Published 2025-07-28 · Analyzed
5.5EPSS 0.003
CVE-2025-54537
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
Published 2025-07-28 · Analyzed
5.5EPSS 0.003
CVE-2024-31138
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
Published 2024-03-28 · Modified
5.4EPSS 0.745
CVE-2022-48428
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
Published 2023-03-27 · Modified
5.4EPSS 0.680
CVE-2023-34220
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
Published 2023-05-31 · Modified
5.4EPSS 0.612
CVE-2023-34225
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
Published 2023-05-31 · Modified
5.4EPSS 0.607
CVE-2025-52876
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
Published 2025-06-23 · Analyzed
5.4EPSS 0.376
CVE-2025-47851
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible
Published 2025-05-20 · Analyzed
5.4EPSS 0.027
CVE-2024-47950
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
Published 2024-10-08 · Analyzed
5.4EPSS 0.014
CVE-2024-47951
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
Published 2024-10-08 · Analyzed
5.4EPSS 0.014
CVE-2022-48426
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
Published 2023-03-27 · Modified
5.4EPSS 0.011
CVE-2023-43566
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
Published 2023-09-19 · Modified
5.4EPSS 0.010
CVE-2023-34221
In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
Published 2023-05-31 · Modified
5.4EPSS 0.010
CVE-2023-34229
In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
Published 2023-05-31 · Modified
5.4EPSS 0.010
CVE-2023-38061
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
Published 2023-07-12 · Modified
5.4EPSS 0.010
CVE-2023-38063
In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
Published 2023-07-12 · Modified
5.4EPSS 0.010
CVE-2023-38065
In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible
Published 2023-07-12 · Modified
5.4EPSS 0.010
CVE-2022-48427
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
Published 2023-03-27 · Modified
5.4EPSS 0.010
CVE-2025-52875
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
Published 2025-06-23 · Analyzed
5.4EPSS 0.010
CVE-2024-56352
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
Published 2024-12-20 · Analyzed
5.4EPSS 0.008
CVE-2024-56355
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
Published 2024-12-20 · Analyzed
5.4EPSS 0.008
CVE-2025-47853
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
Published 2025-05-20 · Analyzed
5.4EPSS 0.007
CVE-2025-47852
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
Published 2025-05-20 · Analyzed
5.4EPSS 0.007
CVE-2020-7910
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.
Published 2020-01-30 · Modified
5.4EPSS 0.005
CVE-2025-67741
In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
Published 2025-12-11 · Analyzed
5.4EPSS 0.005
CVE-2021-31908
In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
Published 2021-05-11 · Modified
5.4EPSS 0.005
CVE-2021-3315
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
Published 2021-05-11 · Modified
5.4EPSS 0.005
CVE-2021-43198
In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
Published 2021-11-09 · Modified
5.4EPSS 0.005
CVE-2022-24339
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
Published 2022-02-25 · Modified
5.4EPSS 0.005
CVE-2023-41248
In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration
Published 2023-08-25 · Modified
5.4EPSS 0.004
CVE-2024-24937
In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
Published 2024-02-06 · Modified
5.4EPSS 0.004
CVE-2024-43807
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
Published 2024-08-16 · Analyzed
5.4EPSS 0.003
CVE-2024-36363
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36368
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36369
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36370
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36373
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36374
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
← Prev5 / 7Next →