VYPR

Youtrack

by Jetbrains

CVEs (123)

  • CVE-2025-53959HigJul 15, 2025
    risk 0.49cvss 7.6epss 0.00

    In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible

  • CVE-2023-35053HigJun 12, 2023
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms

  • CVE-2021-37553HigAug 6, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.

  • CVE-2021-37550HigAug 6, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.

  • CVE-2021-31905HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.02

    In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.

  • CVE-2021-31902HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.

  • CVE-2021-25769HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.02

    In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.

  • CVE-2020-25209HigNov 16, 2020
    risk 0.49cvss 7.5epss 0.02

    In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.

  • CVE-2020-15823HigAug 8, 2020
    risk 0.49cvss 7.5epss 0.02

    JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.

  • CVE-2020-11693HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.02

    JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.

  • CVE-2021-43189HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

  • CVE-2021-43188HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

  • CVE-2020-15822HigOct 19, 2020
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.

  • CVE-2026-33392HigApr 17, 2026
    risk 0.47cvss 7.2epss 0.00

    In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

  • CVE-2022-28650HigApr 5, 2022
    risk 0.47cvss 7.3epss 0.01

    In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

  • CVE-2025-24458HigJan 21, 2025
    risk 0.46cvss 7.1epss 0.00

    In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration

  • CVE-2026-49386MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

  • CVE-2026-49385MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

  • CVE-2026-25846MedFeb 9, 2026
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

  • CVE-2024-28230MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

Page 2 of 7