VYPR

Youtrack

by Jetbrains

CVEs (123)

  • CVE-2024-28229MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

  • CVE-2023-38068MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms

  • CVE-2020-24618MedAug 27, 2020
    risk 0.42cvss 6.5epss 0.02

    In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.

  • CVE-2020-15821MedAug 8, 2020
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.

  • CVE-2024-38506MedJun 18, 2024
    risk 0.41cvss 6.3epss 0.00

    In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows

  • CVE-2025-54527MedJul 28, 2025
    risk 0.40cvss 6.1epss 0.00

    In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

  • CVE-2021-31903MedMay 11, 2021
    risk 0.40cvss 6.1epss 0.01

    In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.

  • CVE-2020-7913MedJan 30, 2020
    risk 0.40cvss 6.1epss 0.01

    JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.

  • CVE-2019-16171MedOct 2, 2019
    risk 0.40cvss 6.1epss 0.01

    In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.

  • CVE-2019-15041MedOct 1, 2019
    risk 0.40cvss 6.1epss 0.01

    JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.

  • CVE-2019-14953MedOct 1, 2019
    risk 0.40cvss 6.1epss 0.01

    JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.

  • CVE-2019-14952MedOct 1, 2019
    risk 0.40cvss 6.1epss 0.01

    JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.

  • CVE-2024-35299MedMay 16, 2024
    risk 0.38cvss 5.9epss 0.00

    In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation

  • CVE-2022-28648MedApr 5, 2022
    risk 0.37cvss 5.7epss 0.01

    In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered

  • CVE-2025-24457MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.01

    In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs

  • CVE-2024-50575MedOct 28, 2024
    risk 0.35cvss 5.4epss 0.00

    In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API

  • CVE-2024-48902MedOct 10, 2024
    risk 0.35cvss 5.4epss 0.00

    In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

  • CVE-2022-24347MedFeb 25, 2022
    risk 0.35cvss 5.4epss 0.01

    JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.

  • CVE-2022-24344MedFeb 25, 2022
    risk 0.35cvss 5.4epss 0.01

    JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.

  • CVE-2021-43192MedNov 9, 2021
    risk 0.35cvss 5.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.

Page 3 of 7