VYPR

by Jetbrains

CVEs (48)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-33392Hig0.477.20.00Apr 17, 2026In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
CVE-2024-505820.020.22Oct 28, 2024In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
CVE-2024-505810.020.22Oct 28, 2024In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
CVE-2024-505800.020.24Oct 28, 2024In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
CVE-2024-505780.020.22Oct 28, 2024In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
CVE-2024-505760.020.22Oct 28, 2024In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
CVE-2024-505790.010.08Oct 28, 2024In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
CVE-2024-505770.010.17Oct 28, 2024In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
CVE-2024-505750.010.08Oct 28, 2024In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
CVE-2026-281930.000.00Feb 25, 2026In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
CVE-2026-258460.000.00Feb 9, 2026In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
CVE-2025-647730.000.00Nov 11, 2025In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
CVE-2025-646850.000.00Nov 10, 2025In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
CVE-2025-646840.000.00Nov 10, 2025In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
CVE-2025-577310.000.00Aug 20, 2025In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
CVE-2025-545270.000.00Jul 28, 2025In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
CVE-2025-539590.000.00Jul 15, 2025In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible
CVE-2025-478500.000.00May 20, 2025In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
CVE-2025-483910.000.00May 20, 2025In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
CVE-2025-244580.000.00Jan 21, 2025In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration

Page 1 of 3