Intellij Idea
by Jetbrains
CVEs (82)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-37009 | Low | 0.25 | 3.9 | 0.00 | Jul 28, 2022 | In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible | ||
| CVE-2022-29818 | Low | 0.25 | 3.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed | ||
| CVE-2022-29817 | Low | 0.25 | 3.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible | ||
| CVE-2026-75052 | Low | 0.23 | 3.6 | 0.00 | Aug 17, 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects | ||
| CVE-2022-37010 | Low | 0.23 | 3.6 | 0.00 | Jul 28, 2022 | In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed | ||
| CVE-2026-86505 | Low | 0.21 | 3.3 | 0.00 | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace | ||
| CVE-2026-86503 | Low | 0.21 | 3.3 | 0.00 | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching | ||
| CVE-2026-49383 | Low | 0.21 | 3.3 | 0.00 | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible | ||
| CVE-2025-32054 | Low | 0.21 | 3.3 | 0.00 | Apr 3, 2025 | In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file | ||
| CVE-2024-46970 | Low | 0.21 | 3.3 | 0.00 | Sep 16, 2024 | In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible | ||
| CVE-2023-38069 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2023 | In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases | ||
| CVE-2026-86501 | Low | 0.18 | 2.8 | 0.00 | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log | ||
| CVE-2024-24940 | Low | 0.18 | 2.8 | 0.00 | Feb 6, 2024 | In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives | ||
| CVE-2022-29816 | Low | 0.18 | 2.8 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible | ||
| CVE-2022-29812 | Low | 0.15 | 2.3 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient | ||
| CVE-2026-64815 | Hig | 0.00 | 8.1 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | ||
| CVE-2026-64814 | Hig | 0.00 | 8.6 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | ||
| CVE-2026-64813 | Cri | 0.00 | 10.0 | 0.01 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | ||
| CVE-2026-64812 | Cri | 0.00 | 10.0 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | ||
| CVE-2026-64811 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration |
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
- risk 0.23cvss 3.6epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects
- risk 0.23cvss 3.6epss 0.00
In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases
- risk 0.18cvss 2.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log
- risk 0.18cvss 2.8epss 0.00
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
- risk 0.18cvss 2.8epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
- risk 0.15cvss 2.3epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
- risk 0.00cvss 8.1epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
- risk 0.00cvss 8.6epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
- risk 0.00cvss 10.0epss 0.01
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- risk 0.00cvss 10.0epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- risk 0.00cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
Page 4 of 5