Youtrack
by Jetbrains
CVEs (153)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24366 | Low | 0.21 | 3.3 | 0.00 | Nov 16, 2020 | Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups. | ||
| CVE-2026-86487 | Low | 0.20 | 3.1 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | ||
| CVE-2024-54153 | Low | 0.20 | 3.1 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | ||
| CVE-2025-64773 | Low | 0.18 | 2.7 | 0.00 | Nov 11, 2025 | In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit | ||
| CVE-2020-11692 | Low | 0.18 | 2.7 | 0.01 | Apr 22, 2020 | In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators. | ||
| CVE-2026-61492 | Low | 0.00 | 3.5 | 0.01 | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible | ||
| CVE-2026-59791 | Low | 0.00 | 3.5 | 0.00 | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible | ||
| CVE-2026-57926 | Low | 0.00 | 2.6 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack | ||
| CVE-2026-57925 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags | ||
| CVE-2026-57924 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details | ||
| CVE-2026-57923 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings | ||
| CVE-2026-57922 | Low | 0.00 | 3.1 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible | ||
| CVE-2026-57921 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint |
- risk 0.21cvss 3.3epss 0.00
Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.
- risk 0.20cvss 3.1epss 0.00
In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content
- risk 0.20cvss 3.1epss 0.00
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
- risk 0.18cvss 2.7epss 0.00
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
- risk 0.18cvss 2.7epss 0.01
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
- risk 0.00cvss 3.5epss 0.01
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
- risk 0.00cvss 3.5epss 0.00
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
- risk 0.00cvss 2.6epss 0.00
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
- risk 0.00cvss 5.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
- risk 0.00cvss 3.1epss 0.00
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
Page 8 of 8