VendorsJetBrainsteamcityany version
Vulnerabilities

JetBrains TeamCity any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

265CVEs
CVE-2025-52876
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
Published 2025-06-23 · Analyzed
5.4EPSS 0.376
CVE-2025-47851
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible
Published 2025-05-20 · Analyzed
5.4EPSS 0.027
CVE-2024-47950
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
Published 2024-10-08 · Analyzed
5.4EPSS 0.014
CVE-2024-47951
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
Published 2024-10-08 · Analyzed
5.4EPSS 0.014
CVE-2023-43566
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
Published 2023-09-19 · Modified
5.4EPSS 0.010
CVE-2023-34221
In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
Published 2023-05-31 · Modified
5.4EPSS 0.010
CVE-2023-34229
In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
Published 2023-05-31 · Modified
5.4EPSS 0.010
CVE-2023-38061
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
Published 2023-07-12 · Modified
5.4EPSS 0.010
CVE-2023-38063
In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
Published 2023-07-12 · Modified
5.4EPSS 0.010
CVE-2023-38065
In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible
Published 2023-07-12 · Modified
5.4EPSS 0.010
CVE-2022-48427
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
Published 2023-03-27 · Modified
5.4EPSS 0.010
CVE-2025-52875
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
Published 2025-06-23 · Analyzed
5.4EPSS 0.010
CVE-2024-56352
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
Published 2024-12-20 · Analyzed
5.4EPSS 0.008
CVE-2024-56355
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
Published 2024-12-20 · Analyzed
5.4EPSS 0.008
CVE-2025-47853
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
Published 2025-05-20 · Analyzed
5.4EPSS 0.007
CVE-2025-47852
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
Published 2025-05-20 · Analyzed
5.4EPSS 0.007
CVE-2020-7910
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.
Published 2020-01-30 · Modified
5.4EPSS 0.005
CVE-2025-67741
In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
Published 2025-12-11 · Analyzed
5.4EPSS 0.005
CVE-2021-31908
In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
Published 2021-05-11 · Modified
5.4EPSS 0.005
CVE-2021-3315
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
Published 2021-05-11 · Modified
5.4EPSS 0.005
CVE-2021-43198
In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
Published 2021-11-09 · Modified
5.4EPSS 0.005
CVE-2022-24339
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
Published 2022-02-25 · Modified
5.4EPSS 0.005
CVE-2023-41248
In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration
Published 2023-08-25 · Modified
5.4EPSS 0.004
CVE-2024-24937
In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
Published 2024-02-06 · Modified
5.4EPSS 0.004
CVE-2024-43807
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
Published 2024-08-16 · Analyzed
5.4EPSS 0.003
CVE-2024-36363
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36368
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36369
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36370
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36373
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-36374
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-41825
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
Published 2024-07-22 · Modified
5.4EPSS 0.003
CVE-2024-43810
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
Published 2024-08-16 · Analyzed
5.4EPSS 0.003
CVE-2024-36371
In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
Published 2024-05-29 · Analyzed
5.4EPSS 0.003
CVE-2024-43808
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
Published 2024-08-16 · Analyzed
5.4EPSS 0.002
CVE-2024-24942
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
Published 2024-02-06 · Modified
5.3EPSS 0.320
CVE-2023-34223
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
Published 2023-05-31 · Modified
5.3EPSS 0.013
CVE-2019-18366
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
Published 2019-10-31 · Modified
5.3EPSS 0.011
CVE-2021-25772
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
Published 2021-02-03 · Modified
5.3EPSS 0.010
CVE-2020-15829
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
Published 2020-08-08 · Modified
5.3EPSS 0.009
← Prev5 / 7Next →