Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-67742 | Low | 0.25 | 3.8 | 0.01 | Dec 11, 2025 | In JetBrains TeamCity before 2025.11 path traversal was possible via file upload | ||
| CVE-2025-46618 | Low | 0.25 | 3.5 | 0.59 | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab | ||
| CVE-2021-25775 | Low | 0.25 | 3.8 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. | ||
| CVE-2025-54529 | Low | 0.24 | 3.7 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration | ||
| CVE-2024-43808 | Low | 0.24 | 3.7 | 0.00 | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin | ||
| CVE-2022-29929 | Low | 0.24 | 3.7 | 0.00 | May 12, 2022 | In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible | ||
| CVE-2025-68163 | Low | 0.23 | 3.5 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page | ||
| CVE-2024-47951 | Low | 0.23 | 3.5 | 0.01 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings | ||
| CVE-2024-47950 | Low | 0.23 | 3.5 | 0.01 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings | ||
| CVE-2024-43809 | Low | 0.23 | 3.5 | 0.00 | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page | ||
| CVE-2024-41829 | Low | 0.23 | 3.5 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection | ||
| CVE-2024-41826 | Low | 0.23 | 3.5 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page | ||
| CVE-2024-35300 | Low | 0.23 | 3.5 | 0.00 | May 16, 2024 | In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible | ||
| CVE-2023-43566 | Low | 0.23 | 3.5 | 0.01 | Sep 19, 2023 | In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration | ||
| CVE-2023-41250 | Low | 0.23 | 3.5 | 0.00 | Aug 25, 2023 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration | ||
| CVE-2026-49381 | Low | 0.22 | 3.4 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | ||
| CVE-2022-38133 | Low | 0.21 | 3.2 | 0.00 | Aug 10, 2022 | In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases | ||
| CVE-2021-26309 | Low | 0.21 | 3.3 | 0.00 | May 11, 2021 | Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions. | ||
| CVE-2026-49380 | Low | 0.20 | 3.1 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | ||
| CVE-2025-67739 | Low | 0.20 | 3.1 | 0.00 | Dec 11, 2025 | In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure |
- risk 0.25cvss 3.8epss 0.01
In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
- risk 0.25cvss 3.5epss 0.59
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
- risk 0.25cvss 3.8epss 0.01
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
- risk 0.24cvss 3.7epss 0.00
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
- risk 0.24cvss 3.7epss 0.00
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
- risk 0.24cvss 3.7epss 0.00
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
- risk 0.23cvss 3.5epss 0.01
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
- risk 0.23cvss 3.5epss 0.01
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
- risk 0.23cvss 3.5epss 0.01
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
- risk 0.22cvss 3.4epss 0.00
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
- risk 0.21cvss 3.2epss 0.00
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
- risk 0.21cvss 3.3epss 0.00
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
- risk 0.20cvss 3.1epss 0.00
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
- risk 0.20cvss 3.1epss 0.00
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
Page 13 of 14