Youtrack
by Jetbrains
CVEs (153)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-49369 | Med | 0.28 | 4.3 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages | ||
| CVE-2025-64684 | Med | 0.28 | 4.3 | 0.00 | Nov 10, 2025 | In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form | ||
| CVE-2025-47850 | Med | 0.28 | 4.3 | 0.00 | May 20, 2025 | In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning | ||
| CVE-2024-54157 | Med | 0.28 | 4.3 | 0.01 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector | ||
| CVE-2024-47160 | Med | 0.28 | 4.3 | 0.00 | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | ||
| CVE-2024-47159 | Med | 0.28 | 4.3 | 0.00 | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project | ||
| CVE-2024-38504 | Med | 0.28 | 4.3 | 0.00 | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles | ||
| CVE-2023-50871 | Med | 0.28 | 4.3 | 0.00 | Dec 15, 2023 | In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed | ||
| CVE-2022-24343 | Med | 0.28 | 4.3 | 0.01 | Feb 25, 2022 | In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions. | ||
| CVE-2021-37554 | Med | 0.28 | 4.3 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions. | ||
| CVE-2021-25771 | Med | 0.28 | 4.3 | 0.02 | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed. | ||
| CVE-2019-14956 | Med | 0.28 | 4.3 | 0.01 | Oct 2, 2019 | JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names. | ||
| CVE-2024-54156 | Med | 0.27 | 4.2 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack | ||
| CVE-2024-47162 | Med | 0.27 | 4.1 | 0.00 | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page | ||
| CVE-2026-86486 | Low | 0.24 | 3.7 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | ||
| CVE-2024-54155 | Low | 0.24 | 3.7 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | ||
| CVE-2026-86491 | Low | 0.23 | 3.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads | ||
| CVE-2024-54158 | Low | 0.23 | 3.5 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | ||
| CVE-2026-49370 | Low | 0.22 | 3.4 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests | ||
| CVE-2026-86485 | Low | 0.21 | 3.3 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks |
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
- risk 0.28cvss 4.3epss 0.01
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
- risk 0.28cvss 4.3epss 0.01
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
- risk 0.28cvss 4.3epss 0.01
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
- risk 0.28cvss 4.3epss 0.02
In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.
- risk 0.28cvss 4.3epss 0.01
JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.
- risk 0.27cvss 4.2epss 0.00
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
- risk 0.27cvss 4.1epss 0.00
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
- risk 0.24cvss 3.7epss 0.00
In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
- risk 0.24cvss 3.7epss 0.00
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
- risk 0.23cvss 3.5epss 0.00
In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
- risk 0.23cvss 3.5epss 0.00
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
- risk 0.22cvss 3.4epss 0.00
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
- risk 0.21cvss 3.3epss 0.00
In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks
Page 7 of 8