Youtrack
by Jetbrains
CVEs (153)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-43189 | Hig | 0.48 | 7.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. | ||
| CVE-2021-43188 | Hig | 0.48 | 7.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. | ||
| CVE-2020-15822 | Hig | 0.48 | 7.3 | 0.01 | Oct 19, 2020 | In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped. | ||
| CVE-2026-33392 | Hig | 0.47 | 7.2 | 0.00 | Apr 17, 2026 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass | ||
| CVE-2022-28650 | Hig | 0.47 | 7.3 | 0.01 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI | ||
| CVE-2026-75050 | Hig | 0.46 | 7.1 | 0.01 | Aug 17, 2026 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | ||
| CVE-2025-24458 | Hig | 0.46 | 7.1 | 0.00 | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | ||
| CVE-2026-86497 | Med | 0.44 | 6.8 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials | ||
| CVE-2026-86495 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects | ||
| CVE-2026-86493 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards | ||
| CVE-2026-86490 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint | ||
| CVE-2026-86489 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations | ||
| CVE-2026-86488 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches | ||
| CVE-2026-75049 | Med | 0.42 | 6.5 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | ||
| CVE-2026-75047 | Med | 0.42 | 6.5 | 0.01 | Aug 17, 2026 | In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | ||
| CVE-2026-49386 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas | ||
| CVE-2026-49385 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts | ||
| CVE-2026-25846 | Med | 0.42 | 6.5 | 0.01 | Feb 9, 2026 | In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs | ||
| CVE-2024-28230 | Med | 0.42 | 6.5 | 0.01 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions | ||
| CVE-2024-28229 | Med | 0.42 | 6.5 | 0.01 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles |
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
- risk 0.47cvss 7.2epss 0.00
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
- risk 0.47cvss 7.3epss 0.01
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
- risk 0.46cvss 7.1epss 0.01
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
- risk 0.46cvss 7.1epss 0.00
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
- risk 0.44cvss 6.8epss 0.00
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
Page 3 of 8