VendorsJetBrainsyoutrackall versions
Vulnerabilities

JetBrains YouTrack

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

125CVEs
CVE-2026-62422
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
Published 2026-07-14 · Analyzed
10.0EPSS 0.003
CVE-2022-24442
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
Published 2022-02-25 · Modified
9.8EPSS 0.038
CVE-2021-25770
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
Published 2021-02-03 · Modified
9.8EPSS 0.035
CVE-2019-12850
A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.
Published 2019-07-03 · Modified
9.8EPSS 0.021
CVE-2021-43185
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
Published 2021-11-09 · Modified
9.8EPSS 0.020
CVE-2019-12867
Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
Published 2019-07-03 · Modified
9.8EPSS 0.020
CVE-2019-12866
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
Published 2019-07-03 · Modified
9.8EPSS 0.019
CVE-2019-12852
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
Published 2019-07-03 · Modified
9.8EPSS 0.018
CVE-2024-54154
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
Published 2024-12-04 · Analyzed
9.8EPSS 0.007
CVE-2026-57926
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Published 2026-06-26 · Analyzed
9.8EPSS 0.003
CVE-2021-37549
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
Published 2021-08-06 · Modified
9.1EPSS 0.013
CVE-2026-75045
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
Published 2026-08-17 · Analyzed
9.1EPSS 0.003
CVE-2020-15817
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
Published 2020-08-08 · Modified
8.8EPSS 0.020
CVE-2019-15040
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
Published 2019-10-02 · Modified
8.8EPSS 0.008
CVE-2019-12851
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
Published 2019-07-03 · Modified
8.8EPSS 0.008
CVE-2021-25765
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
Published 2021-02-03 · Modified
8.8EPSS 0.007
CVE-2026-28193
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
Published 2026-02-25 · Analyzed
8.8EPSS 0.003
CVE-2025-57731
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
Published 2025-08-20 · Analyzed
8.7EPSS 0.003
CVE-2026-49368
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
Published 2026-05-29 · Analyzed
8.7EPSS 0.002
CVE-2026-75048
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
Published 2026-08-17 · Analyzed
8.2EPSS 0.002
CVE-2024-49579
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
Published 2024-10-17 · Analyzed
8.1EPSS 0.004
CVE-2024-38506
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows
Published 2024-06-18 · Modified
8.1EPSS 0.003
CVE-2026-75044
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
Published 2026-08-17 · Analyzed
8.1EPSS 0.002
CVE-2026-75051
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
Published 2026-08-17 · Analyzed
8.1EPSS 0.002
CVE-2025-64685
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
Published 2025-11-10 · Analyzed
8.1EPSS 0.002
CVE-2025-24458
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
Published 2025-01-21 · Analyzed
7.8EPSS 0.002
CVE-2025-48391
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
Published 2025-05-20 · Analyzed
7.7EPSS 0.004
CVE-2025-53959
In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible
Published 2025-07-15 · Analyzed
7.6EPSS 0.003
CVE-2020-25209
In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.
Published 2020-11-16 · Modified
7.5EPSS 0.024
CVE-2020-15823
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
Published 2020-08-08 · Modified
7.5EPSS 0.020
CVE-2021-31905
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
Published 2021-05-11 · Modified
7.5EPSS 0.019
CVE-2020-11693
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
Published 2020-04-22 · Modified
7.5EPSS 0.018
CVE-2021-25769
In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
Published 2021-02-03 · Modified
7.5EPSS 0.018
CVE-2021-37553
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
Published 2021-08-06 · Modified
7.5EPSS 0.015
CVE-2020-15822
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
Published 2020-10-19 · Modified
7.5EPSS 0.014
CVE-2021-31902
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
Published 2021-05-11 · Modified
7.5EPSS 0.012
CVE-2021-37550
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
Published 2021-08-06 · Modified
7.5EPSS 0.011
CVE-2024-50574
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
Published 2024-10-28 · Analyzed
7.5EPSS 0.006
CVE-2023-35053
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
Published 2023-06-12 · Modified
7.5EPSS 0.006
CVE-2024-38505
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
Published 2024-06-18 · Modified
7.5EPSS 0.004
1 / 4Next →