Youtrack
by Jetbrains
CVEs (123)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-18369 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible. | ||
| CVE-2024-50574 | Med | 0.34 | 5.3 | 0.01 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality | ||
| CVE-2024-38505 | Med | 0.34 | 5.3 | 0.00 | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site | ||
| CVE-2024-28228 | Med | 0.34 | 5.3 | 0.00 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible | ||
| CVE-2024-50582 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements | ||
| CVE-2024-50581 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag | ||
| CVE-2024-50580 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule | ||
| CVE-2024-50579 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible | ||
| CVE-2024-50578 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page | ||
| CVE-2024-50577 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings | ||
| CVE-2024-50576 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest | ||
| CVE-2024-22370 | Med | 0.30 | 4.6 | 0.00 | Jan 9, 2024 | In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible | ||
| CVE-2023-35054 | Med | 0.30 | 4.6 | 0.01 | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible | ||
| CVE-2022-28649 | Med | 0.30 | 4.6 | 0.00 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description | ||
| CVE-2026-49369 | Med | 0.28 | 4.3 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages | ||
| CVE-2025-64684 | Med | 0.28 | 4.3 | 0.00 | Nov 10, 2025 | In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form | ||
| CVE-2025-47850 | Med | 0.28 | 4.3 | 0.00 | May 20, 2025 | In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning | ||
| CVE-2024-54157 | Med | 0.28 | 4.3 | 0.01 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector | ||
| CVE-2024-47160 | Med | 0.28 | 4.3 | 0.00 | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | ||
| CVE-2024-47159 | Med | 0.28 | 4.3 | 0.00 | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project |
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
- risk 0.34cvss 5.3epss 0.01
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
- risk 0.34cvss 5.3epss 0.00
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
- risk 0.34cvss 5.3epss 0.00
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
- risk 0.28cvss 4.3epss 0.01
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
Page 5 of 7