Youtrack
by Jetbrains
CVEs (123)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38504 | Med | 0.28 | 4.3 | 0.00 | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles | ||
| CVE-2023-50871 | Med | 0.28 | 4.3 | 0.00 | Dec 15, 2023 | In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed | ||
| CVE-2022-24343 | Med | 0.28 | 4.3 | 0.01 | Feb 25, 2022 | In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions. | ||
| CVE-2021-37554 | Med | 0.28 | 4.3 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions. | ||
| CVE-2021-25771 | Med | 0.28 | 4.3 | 0.02 | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed. | ||
| CVE-2019-14956 | Med | 0.28 | 4.3 | 0.01 | Oct 2, 2019 | JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names. | ||
| CVE-2024-54156 | Med | 0.27 | 4.2 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack | ||
| CVE-2024-47162 | Med | 0.27 | 4.1 | 0.00 | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page | ||
| CVE-2024-54155 | Low | 0.24 | 3.7 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | ||
| CVE-2024-54158 | Low | 0.23 | 3.5 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | ||
| CVE-2026-49370 | Low | 0.22 | 3.4 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests | ||
| CVE-2020-24366 | Low | 0.21 | 3.3 | 0.00 | Nov 16, 2020 | Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups. | ||
| CVE-2024-54153 | Low | 0.20 | 3.1 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | ||
| CVE-2025-64773 | Low | 0.18 | 2.7 | 0.00 | Nov 11, 2025 | In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit | ||
| CVE-2020-11692 | Low | 0.18 | 2.7 | 0.01 | Apr 22, 2020 | In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators. | ||
| CVE-2026-61492 | Low | 0.00 | 3.5 | 0.00 | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible | ||
| CVE-2026-59791 | Low | 0.00 | 3.5 | 0.00 | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible | ||
| CVE-2026-57926 | Low | 0.00 | 2.6 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack | ||
| CVE-2026-57925 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags | ||
| CVE-2026-57924 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details |
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
- risk 0.28cvss 4.3epss 0.01
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
- risk 0.28cvss 4.3epss 0.01
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
- risk 0.28cvss 4.3epss 0.02
In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.
- risk 0.28cvss 4.3epss 0.01
JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.
- risk 0.27cvss 4.2epss 0.00
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
- risk 0.27cvss 4.1epss 0.00
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
- risk 0.24cvss 3.7epss 0.00
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
- risk 0.23cvss 3.5epss 0.00
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
- risk 0.22cvss 3.4epss 0.00
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
- risk 0.21cvss 3.3epss 0.00
Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.
- risk 0.20cvss 3.1epss 0.00
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
- risk 0.18cvss 2.7epss 0.00
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
- risk 0.18cvss 2.7epss 0.01
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
- risk 0.00cvss 3.5epss 0.00
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
- risk 0.00cvss 3.5epss 0.00
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
- risk 0.00cvss 2.6epss 0.00
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
Page 6 of 7