VYPR

Youtrack

by Jetbrains

CVEs (123)

  • CVE-2024-38504MedJun 18, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles

  • CVE-2023-50871MedDec 15, 2023
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed

  • CVE-2022-24343MedFeb 25, 2022
    risk 0.28cvss 4.3epss 0.01

    In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.

  • CVE-2021-37554MedAug 6, 2021
    risk 0.28cvss 4.3epss 0.01

    In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

  • CVE-2021-25771MedFeb 3, 2021
    risk 0.28cvss 4.3epss 0.02

    In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.

  • CVE-2019-14956MedOct 2, 2019
    risk 0.28cvss 4.3epss 0.01

    JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.

  • CVE-2024-54156MedDec 4, 2024
    risk 0.27cvss 4.2epss 0.00

    In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack

  • CVE-2024-47162MedSep 19, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

  • CVE-2024-54155LowDec 4, 2024
    risk 0.24cvss 3.7epss 0.00

    In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

  • CVE-2024-54158LowDec 4, 2024
    risk 0.23cvss 3.5epss 0.00

    In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

  • CVE-2026-49370LowMay 29, 2026
    risk 0.22cvss 3.4epss 0.00

    In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

  • CVE-2020-24366LowNov 16, 2020
    risk 0.21cvss 3.3epss 0.00

    Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

  • CVE-2024-54153LowDec 4, 2024
    risk 0.20cvss 3.1epss 0.00

    In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

  • CVE-2025-64773LowNov 11, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit

  • CVE-2020-11692LowApr 22, 2020
    risk 0.18cvss 2.7epss 0.01

    In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.

  • CVE-2026-61492LowJul 10, 2026
    risk 0.00cvss 3.5epss 0.00

    In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

  • CVE-2026-59791LowJul 10, 2026
    risk 0.00cvss 3.5epss 0.00

    In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

  • CVE-2026-57926LowJun 26, 2026
    risk 0.00cvss 2.6epss 0.00

    In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

  • CVE-2026-57925MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

  • CVE-2026-57924MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Page 6 of 7