VendorsJetBrainsteamcityall versions
Vulnerabilities

JetBrains TeamCity

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

275CVEs
CVE-2022-29928
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
Published 2022-05-12 · Modified
4.9EPSS 0.005
CVE-2024-31140
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools
Published 2024-03-28 · Analyzed
4.9EPSS 0.004
CVE-2025-52877
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
Published 2025-06-23 · Analyzed
4.8EPSS 0.367
CVE-2025-52879
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
Published 2025-06-23 · Analyzed
4.8EPSS 0.012
CVE-2025-54534
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
Published 2025-07-28 · Analyzed
4.8EPSS 0.008
CVE-2023-34224
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
Published 2023-05-31 · Modified
4.8EPSS 0.003
CVE-2024-41826
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
Published 2024-07-22 · Modified
4.8EPSS 0.003
CVE-2026-49381
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
Published 2026-05-29 · Analyzed
4.8EPSS 0.003
CVE-2025-68163
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
Published 2025-12-16 · Analyzed
4.8EPSS 0.002
CVE-2014-10036
Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.
Published 2015-01-13 · Modified
4.3EPSS 0.019
CVE-2026-49377
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
Published 2026-05-29 · Analyzed
4.3EPSS 0.009
CVE-2020-7908
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
Published 2020-01-30 · Modified
4.3EPSS 0.008
CVE-2019-18365
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
Published 2019-10-31 · Modified
4.3EPSS 0.008
CVE-2019-12846
A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.
Published 2019-07-03 · Modified
4.3EPSS 0.008
CVE-2020-27628
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
Published 2020-11-16 · Modified
4.3EPSS 0.007
CVE-2021-25774
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
Published 2021-02-03 · Modified
4.3EPSS 0.007
CVE-2020-15826
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
Published 2020-08-08 · Modified
4.3EPSS 0.006
CVE-2024-28173
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
Published 2024-03-06 · Analyzed
4.3EPSS 0.005
CVE-2025-52878
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
Published 2025-06-23 · Analyzed
4.3EPSS 0.004
CVE-2023-34219
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
Published 2023-05-31 · Modified
4.3EPSS 0.004
CVE-2026-49378
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
Published 2026-05-29 · Analyzed
4.3EPSS 0.003
CVE-2024-56350
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
Published 2024-12-20 · Analyzed
4.3EPSS 0.003
CVE-2024-56348
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
Published 2024-12-20 · Analyzed
4.3EPSS 0.003
CVE-2025-24460
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
Published 2025-01-21 · Analyzed
4.3EPSS 0.003
CVE-2026-28195
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
Published 2026-02-25 · Analyzed
4.3EPSS 0.003
CVE-2025-54533
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
Published 2025-07-28 · Analyzed
4.3EPSS 0.002
CVE-2025-54532
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
Published 2025-07-28 · Analyzed
4.3EPSS 0.002
CVE-2025-59455
In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
Published 2025-09-17 · Analyzed
4.2EPSS 0.004
CVE-2020-11686
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
Published 2020-04-22 · Modified
4.0EPSS 0.007
CVE-2021-31906
In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.
Published 2021-05-11 · Modified
4.0EPSS 0.006
CVE-2021-26309
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
Published 2021-05-11 · Modified
3.3EPSS 0.002
CVE-2025-67739
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
Published 2025-12-11 · Analyzed
3.1EPSS 0.002
CVE-2025-68164
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
Published 2025-12-16 · Analyzed
2.7EPSS 0.002
CVE-2025-68162
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
Published 2025-12-16 · Analyzed
2.7EPSS 0.002
CVE-2026-28196
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
Published 2026-02-25 · Analyzed
2.3EPSS 0.002
← Prev7 / 7