Youtrack
by Jetbrains
CVEs (153)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-86479 | Hig | 0.53 | 8.1 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | ||
| CVE-2026-75051 | Hig | 0.53 | 8.1 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | ||
| CVE-2026-75048 | Hig | 0.53 | 8.2 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | ||
| CVE-2026-75044 | Hig | 0.53 | 8.1 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | ||
| CVE-2025-64685 | Hig | 0.53 | 8.1 | 0.00 | Nov 10, 2025 | In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure | ||
| CVE-2024-49579 | Hig | 0.53 | 8.1 | 0.00 | Oct 17, 2024 | In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests | ||
| CVE-2024-54154 | Hig | 0.52 | 8.0 | 0.01 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | ||
| CVE-2026-86498 | Hig | 0.50 | 7.7 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission | ||
| CVE-2026-86494 | Hig | 0.50 | 7.7 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues | ||
| CVE-2025-48391 | Hig | 0.50 | 7.7 | 0.00 | May 20, 2025 | In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API | ||
| CVE-2025-53959 | Hig | 0.49 | 7.6 | 0.00 | Jul 15, 2025 | In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible | ||
| CVE-2023-35053 | Hig | 0.49 | 7.5 | 0.01 | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms | ||
| CVE-2021-37553 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used. | ||
| CVE-2021-37550 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. | ||
| CVE-2021-31905 | Hig | 0.49 | 7.5 | 0.02 | May 11, 2021 | In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible. | ||
| CVE-2021-31902 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly. | ||
| CVE-2021-25769 | Hig | 0.49 | 7.5 | 0.02 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments. | ||
| CVE-2020-25209 | Hig | 0.49 | 7.5 | 0.02 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API. | ||
| CVE-2020-15823 | Hig | 0.49 | 7.5 | 0.02 | Aug 8, 2020 | JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component. | ||
| CVE-2020-11693 | Hig | 0.49 | 7.5 | 0.02 | Apr 22, 2020 | JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue. |
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
- risk 0.53cvss 8.2epss 0.00
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
- risk 0.52cvss 8.0epss 0.01
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
- risk 0.50cvss 7.7epss 0.00
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
- risk 0.50cvss 7.7epss 0.00
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
- risk 0.50cvss 7.7epss 0.00
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
- risk 0.49cvss 7.6epss 0.00
In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.
- risk 0.49cvss 7.5epss 0.02
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
- risk 0.49cvss 7.5epss 0.02
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
Page 2 of 8