Youtrack
by Jetbrains
CVEs (153)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7912 | Med | 0.35 | 5.3 | 0.01 | Jan 30, 2020 | In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. | ||
| CVE-2019-18369 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible. | ||
| CVE-2024-50574 | Med | 0.34 | 5.3 | 0.01 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality | ||
| CVE-2024-38505 | Med | 0.34 | 5.3 | 0.00 | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site | ||
| CVE-2024-28228 | Med | 0.34 | 5.3 | 0.00 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible | ||
| CVE-2026-86484 | Med | 0.30 | 4.6 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | ||
| CVE-2024-50582 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements | ||
| CVE-2024-50581 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag | ||
| CVE-2024-50580 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule | ||
| CVE-2024-50579 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible | ||
| CVE-2024-50578 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page | ||
| CVE-2024-50577 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings | ||
| CVE-2024-50576 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest | ||
| CVE-2024-22370 | Med | 0.30 | 4.6 | 0.00 | Jan 9, 2024 | In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible | ||
| CVE-2023-35054 | Med | 0.30 | 4.6 | 0.01 | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible | ||
| CVE-2022-28649 | Med | 0.30 | 4.6 | 0.00 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description | ||
| CVE-2026-86499 | Med | 0.28 | 4.3 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission | ||
| CVE-2026-86496 | Med | 0.28 | 4.3 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses | ||
| CVE-2026-86481 | Med | 0.28 | 4.3 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | ||
| CVE-2026-75046 | Med | 0.28 | 4.3 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint |
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
- risk 0.34cvss 5.3epss 0.01
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
- risk 0.34cvss 5.3epss 0.00
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
- risk 0.34cvss 5.3epss 0.00
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
Page 6 of 8