Intellij Idea
by Jetbrains
CVEs (70)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-8316 | Hig | 0.49 | 7.5 | 0.02 | Aug 3, 2018 | IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml. | ||
| CVE-2026-41882 | Hig | 0.48 | 7.4 | 0.00 | Apr 30, 2026 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server | ||
| CVE-2020-7904 | Hig | 0.48 | 7.4 | 0.01 | Jan 30, 2020 | In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS. | ||
| CVE-2019-10103 | Hig | 0.46 | 8.1 | 0.01 | Jul 3, 2019 | JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101. | ||
| CVE-2022-29819 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible | ||
| CVE-2022-29815 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible | ||
| CVE-2022-29814 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible | ||
| CVE-2022-29813 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible | ||
| CVE-2025-57729 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start | ||
| CVE-2025-57728 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files | ||
| CVE-2023-51655 | Med | 0.41 | 6.3 | 0.00 | Dec 21, 2023 | In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration | ||
| CVE-2024-24941 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2024 | In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL | ||
| CVE-2022-48433 | Med | 0.40 | 6.1 | 0.01 | Mar 29, 2023 | In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server. | ||
| CVE-2022-46826 | Med | 0.40 | 6.2 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability. | ||
| CVE-2019-14954 | Med | 0.38 | 5.9 | 0.01 | Oct 1, 2019 | JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection. | ||
| CVE-2022-48430 | Med | 0.36 | 5.5 | 0.00 | Mar 29, 2023 | In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview. | ||
| CVE-2022-46824 | Med | 0.36 | 5.6 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible. | ||
| CVE-2025-68269 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH | ||
| CVE-2021-25756 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS. | ||
| CVE-2020-27622 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version. |
- risk 0.49cvss 7.5epss 0.02
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
- risk 0.48cvss 7.4epss 0.00
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
- risk 0.48cvss 7.4epss 0.01
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
- risk 0.46cvss 8.1epss 0.01
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
- risk 0.42cvss 6.5epss 0.00
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
- risk 0.42cvss 6.5epss 0.00
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
- risk 0.41cvss 6.3epss 0.00
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
- risk 0.40cvss 6.1epss 0.00
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
- risk 0.40cvss 6.1epss 0.01
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
- risk 0.40cvss 6.2epss 0.00
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
- risk 0.38cvss 5.9epss 0.01
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
- risk 0.36cvss 5.5epss 0.00
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
- risk 0.36cvss 5.6epss 0.00
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
- risk 0.35cvss 5.4epss 0.00
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
- risk 0.35cvss 5.3epss 0.01
In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.
- risk 0.35cvss 5.3epss 0.01
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
Page 2 of 4