VYPR

Youtrack

by Jetbrains

CVEs (153)

  • CVE-2020-24366LowNov 16, 2020
    risk 0.21cvss 3.3epss 0.00

    Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

  • CVE-2026-86487LowSep 7, 2026
    risk 0.20cvss 3.1epss 0.00

    In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

  • CVE-2024-54153LowDec 4, 2024
    risk 0.20cvss 3.1epss 0.00

    In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

  • CVE-2025-64773LowNov 11, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit

  • CVE-2020-11692LowApr 22, 2020
    risk 0.18cvss 2.7epss 0.01

    In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.

  • CVE-2026-61492LowJul 10, 2026
    risk 0.00cvss 3.5epss 0.01

    In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

  • CVE-2026-59791LowJul 10, 2026
    risk 0.00cvss 3.5epss 0.00

    In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

  • CVE-2026-57926LowJun 26, 2026
    risk 0.00cvss 2.6epss 0.00

    In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

  • CVE-2026-57925MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

  • CVE-2026-57924MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

  • CVE-2026-57923MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

  • CVE-2026-57922LowJun 26, 2026
    risk 0.00cvss 3.1epss 0.00

    In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

  • CVE-2026-57921MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

Page 8 of 8