VYPR

Youtrack

by Jetbrains

CVEs (153)

  • CVE-2021-43189HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

  • CVE-2021-43188HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

  • CVE-2020-15822HigOct 19, 2020
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.

  • CVE-2026-33392HigApr 17, 2026
    risk 0.47cvss 7.2epss 0.00

    In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

  • CVE-2022-28650HigApr 5, 2022
    risk 0.47cvss 7.3epss 0.01

    In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

  • CVE-2026-75050HigAug 17, 2026
    risk 0.46cvss 7.1epss 0.01

    In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

  • CVE-2025-24458HigJan 21, 2025
    risk 0.46cvss 7.1epss 0.00

    In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration

  • CVE-2026-86497MedSep 7, 2026
    risk 0.44cvss 6.8epss 0.00

    In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

  • CVE-2026-86495MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects

  • CVE-2026-86493MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

  • CVE-2026-86490MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

  • CVE-2026-86489MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations

  • CVE-2026-86488MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches

  • CVE-2026-75049MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

  • CVE-2026-75047MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

  • CVE-2026-49386MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

  • CVE-2026-49385MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

  • CVE-2026-25846MedFeb 9, 2026
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

  • CVE-2024-28230MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

  • CVE-2024-28229MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

Page 3 of 8