Youtrack
by Jetbrains
CVEs (123)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-53959 | Hig | 0.49 | 7.6 | 0.00 | Jul 15, 2025 | In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible | ||
| CVE-2023-35053 | Hig | 0.49 | 7.5 | 0.01 | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms | ||
| CVE-2021-37553 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used. | ||
| CVE-2021-37550 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. | ||
| CVE-2021-31905 | Hig | 0.49 | 7.5 | 0.02 | May 11, 2021 | In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible. | ||
| CVE-2021-31902 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly. | ||
| CVE-2021-25769 | Hig | 0.49 | 7.5 | 0.02 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments. | ||
| CVE-2020-25209 | Hig | 0.49 | 7.5 | 0.02 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API. | ||
| CVE-2020-15823 | Hig | 0.49 | 7.5 | 0.02 | Aug 8, 2020 | JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component. | ||
| CVE-2020-11693 | Hig | 0.49 | 7.5 | 0.02 | Apr 22, 2020 | JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue. | ||
| CVE-2021-43189 | Hig | 0.48 | 7.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. | ||
| CVE-2021-43188 | Hig | 0.48 | 7.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. | ||
| CVE-2020-15822 | Hig | 0.48 | 7.3 | 0.01 | Oct 19, 2020 | In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped. | ||
| CVE-2026-33392 | Hig | 0.47 | 7.2 | 0.00 | Apr 17, 2026 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass | ||
| CVE-2022-28650 | Hig | 0.47 | 7.3 | 0.01 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI | ||
| CVE-2025-24458 | Hig | 0.46 | 7.1 | 0.00 | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | ||
| CVE-2026-49386 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas | ||
| CVE-2026-49385 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts | ||
| CVE-2026-25846 | Med | 0.42 | 6.5 | 0.01 | Feb 9, 2026 | In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs | ||
| CVE-2024-28230 | Med | 0.42 | 6.5 | 0.01 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions |
- risk 0.49cvss 7.6epss 0.00
In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.
- risk 0.49cvss 7.5epss 0.02
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
- risk 0.49cvss 7.5epss 0.02
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
- risk 0.47cvss 7.2epss 0.00
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
- risk 0.47cvss 7.3epss 0.01
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
- risk 0.46cvss 7.1epss 0.00
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions
Page 2 of 7