VYPR

Youtrack

by Jetbrains

CVEs (153)

  • CVE-2026-86479HigSep 7, 2026
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

  • CVE-2026-75051HigAug 17, 2026
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

  • CVE-2026-75048HigAug 17, 2026
    risk 0.53cvss 8.2epss 0.00

    In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

  • CVE-2026-75044HigAug 17, 2026
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

  • CVE-2025-64685HigNov 10, 2025
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

  • CVE-2024-49579HigOct 17, 2024
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests

  • CVE-2024-54154HigDec 4, 2024
    risk 0.52cvss 8.0epss 0.01

    In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

  • CVE-2026-86498HigSep 7, 2026
    risk 0.50cvss 7.7epss 0.00

    In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

  • CVE-2026-86494HigSep 7, 2026
    risk 0.50cvss 7.7epss 0.00

    In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

  • CVE-2025-48391HigMay 20, 2025
    risk 0.50cvss 7.7epss 0.00

    In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

  • CVE-2025-53959HigJul 15, 2025
    risk 0.49cvss 7.6epss 0.00

    In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible

  • CVE-2023-35053HigJun 12, 2023
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms

  • CVE-2021-37553HigAug 6, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.

  • CVE-2021-37550HigAug 6, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.

  • CVE-2021-31905HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.02

    In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.

  • CVE-2021-31902HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.

  • CVE-2021-25769HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.02

    In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.

  • CVE-2020-25209HigNov 16, 2020
    risk 0.49cvss 7.5epss 0.02

    In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.

  • CVE-2020-15823HigAug 8, 2020
    risk 0.49cvss 7.5epss 0.02

    JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.

  • CVE-2020-11693HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.02

    JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.

Page 2 of 8