VYPR

Youtrack

by Jetbrains

CVEs (153)

  • CVE-2020-7912MedJan 30, 2020
    risk 0.35cvss 5.3epss 0.01

    In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.

  • CVE-2019-18369MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.

  • CVE-2024-50574MedOct 28, 2024
    risk 0.34cvss 5.3epss 0.01

    In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality

  • CVE-2024-38505MedJun 18, 2024
    risk 0.34cvss 5.3epss 0.00

    In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

  • CVE-2024-28228MedMar 7, 2024
    risk 0.34cvss 5.3epss 0.00

    In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible

  • CVE-2026-86484MedSep 7, 2026
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS

  • CVE-2024-50582MedOct 28, 2024
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements

  • CVE-2024-50581MedOct 28, 2024
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag

  • CVE-2024-50580MedOct 28, 2024
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule

  • CVE-2024-50579MedOct 28, 2024
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible

  • CVE-2024-50578MedOct 28, 2024
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page

  • CVE-2024-50577MedOct 28, 2024
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings

  • CVE-2024-50576MedOct 28, 2024
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest

  • CVE-2024-22370MedJan 9, 2024
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible

  • CVE-2023-35054MedJun 12, 2023
    risk 0.30cvss 4.6epss 0.01

    In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible

  • CVE-2022-28649MedApr 5, 2022
    risk 0.30cvss 4.6epss 0.00

    In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description

  • CVE-2026-86499MedSep 7, 2026
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission

  • CVE-2026-86496MedSep 7, 2026
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses

  • CVE-2026-86481MedSep 7, 2026
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons

  • CVE-2026-75046MedAug 17, 2026
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

Page 6 of 8