Youtrack
by Jetbrains
CVEs (123)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-28229 | Med | 0.42 | 6.5 | 0.01 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles | ||
| CVE-2023-38068 | Med | 0.42 | 6.5 | 0.01 | Jul 12, 2023 | In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms | ||
| CVE-2020-24618 | Med | 0.42 | 6.5 | 0.02 | Aug 27, 2020 | In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access. | ||
| CVE-2020-15821 | Med | 0.42 | 6.5 | 0.01 | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft. | ||
| CVE-2024-38506 | Med | 0.41 | 6.3 | 0.00 | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows | ||
| CVE-2025-54527 | Med | 0.40 | 6.1 | 0.00 | Jul 28, 2025 | In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions | ||
| CVE-2021-31903 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS. | ||
| CVE-2020-7913 | Med | 0.40 | 6.1 | 0.01 | Jan 30, 2020 | JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description. | ||
| CVE-2019-16171 | Med | 0.40 | 6.1 | 0.01 | Oct 2, 2019 | In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page. | ||
| CVE-2019-15041 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere. | ||
| CVE-2019-14953 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser. | ||
| CVE-2019-14952 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles. | ||
| CVE-2024-35299 | Med | 0.38 | 5.9 | 0.00 | May 16, 2024 | In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation | ||
| CVE-2022-28648 | Med | 0.37 | 5.7 | 0.01 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered | ||
| CVE-2025-24457 | Med | 0.36 | 5.5 | 0.01 | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | ||
| CVE-2024-50575 | Med | 0.35 | 5.4 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API | ||
| CVE-2024-48902 | Med | 0.35 | 5.4 | 0.00 | Oct 10, 2024 | In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API | ||
| CVE-2022-24347 | Med | 0.35 | 5.4 | 0.01 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon. | ||
| CVE-2022-24344 | Med | 0.35 | 5.4 | 0.01 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page. | ||
| CVE-2021-43192 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. |
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
- risk 0.42cvss 6.5epss 0.02
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
- risk 0.41cvss 6.3epss 0.00
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows
- risk 0.40cvss 6.1epss 0.00
In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
- risk 0.40cvss 6.1epss 0.01
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.
- risk 0.40cvss 6.1epss 0.01
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
- risk 0.38cvss 5.9epss 0.00
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
- risk 0.37cvss 5.7epss 0.01
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
- risk 0.36cvss 5.5epss 0.01
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
- risk 0.35cvss 5.4epss 0.00
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
- risk 0.35cvss 5.4epss 0.00
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
- risk 0.35cvss 5.4epss 0.01
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.
- risk 0.35cvss 5.4epss 0.01
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.
Page 3 of 7