VendorsJetBrainsyoutrackall versions
Vulnerabilities

JetBrains YouTrack

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

125CVEs
CVE-2026-49370
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
Published 2026-05-29 · Analyzed
7.5EPSS 0.003
CVE-2025-64684
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
Published 2025-11-10 · Analyzed
7.5EPSS 0.003
CVE-2026-57921
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
Published 2026-06-26 · Analyzed
7.5EPSS 0.003
CVE-2024-35299
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
Published 2024-05-16 · Analyzed
7.5EPSS 0.003
CVE-2026-57923
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
Published 2026-06-26 · Analyzed
7.5EPSS 0.003
CVE-2022-28650
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
Published 2022-04-05 · Modified
7.3EPSS 0.006
CVE-2023-38068
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
Published 2023-07-12 · Modified
7.3EPSS 0.006
CVE-2026-33392
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
Published 2026-04-17 · Analyzed
7.2EPSS 0.005
CVE-2026-75050
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
Published 2026-08-17 · Analyzed
7.1EPSS 0.011
CVE-2020-24618
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
Published 2020-08-27 · Modified
6.5EPSS 0.019
CVE-2026-75047
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
Published 2026-08-17 · Analyzed
6.5EPSS 0.012
CVE-2026-25846
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Published 2026-02-09 · Analyzed
6.5EPSS 0.011
CVE-2020-15821
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
Published 2020-08-08 · Modified
6.5EPSS 0.009
CVE-2024-54157
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
Published 2024-12-04 · Analyzed
6.5EPSS 0.006
CVE-2024-28229
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
Published 2024-03-07 · Analyzed
6.5EPSS 0.005
CVE-2024-28230
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions
Published 2024-03-07 · Analyzed
6.5EPSS 0.005
CVE-2024-54153
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
Published 2024-12-04 · Analyzed
6.5EPSS 0.004
CVE-2024-54156
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
Published 2024-12-04 · Analyzed
6.5EPSS 0.003
CVE-2026-75049
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
Published 2026-08-17 · Analyzed
6.5EPSS 0.003
CVE-2026-49386
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
Published 2026-05-29 · Analyzed
6.5EPSS 0.003
CVE-2026-49385
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
Published 2026-05-29 · Analyzed
6.5EPSS 0.003
CVE-2019-16171
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
Published 2019-10-02 · Modified
6.1EPSS 0.011
CVE-2020-7913
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.
Published 2020-01-30 · Modified
6.1EPSS 0.011
CVE-2019-14952
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
Published 2019-10-01 · Modified
6.1EPSS 0.011
CVE-2019-15041
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
Published 2019-10-01 · Modified
6.1EPSS 0.010
CVE-2019-14953
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
Published 2019-10-01 · Modified
6.1EPSS 0.009
CVE-2021-31903
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
Published 2021-05-11 · Modified
6.1EPSS 0.008
CVE-2026-61492
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
Published 2026-07-10 · Analyzed
6.1EPSS 0.007
CVE-2024-50575
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
Published 2024-10-28 · Analyzed
6.1EPSS 0.004
CVE-2024-50579
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
Published 2024-10-28 · Analyzed
6.1EPSS 0.003
CVE-2025-54527
In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
Published 2025-07-28 · Analyzed
6.1EPSS 0.003
CVE-2022-28648
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
Published 2022-04-05 · Modified
5.7EPSS 0.014
CVE-2025-24457
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
Published 2025-01-21 · Analyzed
5.5EPSS 0.006
CVE-2023-35054
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
Published 2023-06-12 · Modified
5.4EPSS 0.010
CVE-2021-43184
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
Published 2021-11-09 · Modified
5.4EPSS 0.007
CVE-2021-37552
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
Published 2021-08-06 · Modified
5.4EPSS 0.006
CVE-2021-27733
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
Published 2021-05-11 · Modified
5.4EPSS 0.006
CVE-2021-43186
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
Published 2021-11-09 · Modified
5.4EPSS 0.006
CVE-2022-24344
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
Published 2022-02-25 · Modified
5.4EPSS 0.006
CVE-2022-24347
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.
Published 2022-02-25 · Modified
5.4EPSS 0.006
← Prev2 / 4Next →