Vendor CVEs
Jetbrains
All CVEs
650 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48343 | Med | 0.40 | 5.4 | 0.59 | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process. | ||
| CVE-2022-46826 | Med | 0.40 | 6.2 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability. | ||
| CVE-2022-29811 | Med | 0.40 | 6.1 | 0.00 | Apr 28, 2022 | In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible. | ||
| CVE-2022-25261 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS. | ||
| CVE-2022-25259 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS. | ||
| CVE-2022-24338 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS. | ||
| CVE-2022-24330 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible. | ||
| CVE-2021-43181 | Med | 0.40 | 6.1 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, stored XSS is possible. | ||
| CVE-2021-43197 | Med | 0.40 | 6.1 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS. | ||
| CVE-2021-37542 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.3, XSS was possible. | ||
| CVE-2021-37541 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2021 | In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. | ||
| CVE-2021-31911 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. | ||
| CVE-2021-31904 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page. | ||
| CVE-2021-31903 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS. | ||
| CVE-2021-25773 | Med | 0.40 | 6.1 | 0.01 | Feb 3, 2021 | JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages. | ||
| CVE-2021-25757 | Med | 0.40 | 6.1 | 0.01 | Feb 3, 2021 | In JetBrains Hub before 2020.1.12629, an open redirect was possible. | ||
| CVE-2020-27627 | Med | 0.40 | 6.1 | 0.01 | Nov 16, 2020 | JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection. | ||
| CVE-2020-15831 | Med | 0.40 | 6.1 | 0.01 | Aug 8, 2020 | JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI. | ||
| CVE-2020-15830 | Med | 0.40 | 6.1 | 0.01 | Aug 8, 2020 | JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI. | ||
| CVE-2020-7913 | Med | 0.40 | 6.1 | 0.01 | Jan 30, 2020 | JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description. | ||
| CVE-2020-7911 | Med | 0.40 | 6.1 | 0.01 | Jan 30, 2020 | In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS. | ||
| CVE-2019-16171 | Med | 0.40 | 6.1 | 0.01 | Oct 2, 2019 | In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page. | ||
| CVE-2019-15037 | Med | 0.40 | 6.1 | 0.01 | Oct 2, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1. | ||
| CVE-2019-15041 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere. | ||
| CVE-2019-14961 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS. | ||
| CVE-2019-14953 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser. | ||
| CVE-2019-14952 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles. | ||
| CVE-2019-15848 | Med | 0.40 | 6.1 | 0.02 | Sep 5, 2019 | JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user. | ||
| CVE-2019-12844 | Med | 0.40 | 6.1 | 0.01 | Jul 3, 2019 | A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3. | ||
| CVE-2019-12843 | Med | 0.40 | 6.1 | 0.01 | Jul 3, 2019 | A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3. | ||
| CVE-2019-12842 | Med | 0.40 | 6.1 | 0.01 | Jul 3, 2019 | A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2. | ||
| CVE-2026-86506 | Med | 0.38 | 5.9 | 0.00 | Sep 7, 2026 | In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data | ||
| CVE-2026-41153 | Med | 0.38 | 5.8 | 0.00 | Apr 17, 2026 | In JetBrains Junie before 252.549.29 command execution was possible via malicious project file | ||
| CVE-2025-54535 | Med | 0.38 | 5.8 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms | ||
| CVE-2024-56356 | Med | 0.38 | 5.9 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack | ||
| CVE-2024-36378 | Med | 0.38 | 5.9 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens | ||
| CVE-2024-35299 | Med | 0.38 | 5.9 | 0.00 | May 16, 2024 | In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation | ||
| CVE-2024-31139 | Med | 0.38 | 5.9 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector | ||
| CVE-2024-28174 | Med | 0.38 | 5.8 | 0.00 | Mar 6, 2024 | In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly | ||
| CVE-2019-14959 | Med | 0.38 | 5.9 | 0.01 | Oct 2, 2019 | JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection. | ||
| CVE-2019-14954 | Med | 0.38 | 5.9 | 0.01 | Oct 1, 2019 | JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection. | ||
| CVE-2026-53914 | Med | 0.37 | 6.7 | 0.00 | Jun 26, 2026 | In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata | ||
| CVE-2025-59456 | Med | 0.37 | 5.5 | 0.13 | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload | ||
| CVE-2024-24942 | Med | 0.37 | 5.3 | 0.32 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives | ||
| CVE-2022-28648 | Med | 0.37 | 5.7 | 0.01 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered | ||
| CVE-2026-86500 | Med | 0.36 | 5.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin | ||
| CVE-2026-75058 | Med | 0.36 | 5.5 | 0.00 | Aug 17, 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | ||
| CVE-2026-75055 | Med | 0.36 | 5.5 | 0.00 | Aug 17, 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | ||
| CVE-2025-58335 | Med | 0.36 | 5.5 | 0.00 | Aug 28, 2025 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function | ||
| CVE-2025-57733 | Med | 0.36 | 5.5 | 0.00 | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content |
- risk 0.40cvss 5.4epss 0.59
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
- risk 0.40cvss 6.2epss 0.00
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
- risk 0.40cvss 6.1epss 0.00
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
- risk 0.40cvss 6.1epss 0.01
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2020.2.3, XSS was possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
- risk 0.40cvss 6.1epss 0.01
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
- risk 0.40cvss 6.1epss 0.01
In JetBrains Hub before 2020.1.12629, an open redirect was possible.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.
- risk 0.40cvss 6.1epss 0.01
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
- risk 0.40cvss 6.1epss 0.01
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
- risk 0.40cvss 6.1epss 0.02
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
- risk 0.40cvss 6.1epss 0.01
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
- risk 0.40cvss 6.1epss 0.01
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
- risk 0.40cvss 6.1epss 0.01
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
- risk 0.38cvss 5.9epss 0.00
In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data
- risk 0.38cvss 5.8epss 0.00
In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
- risk 0.38cvss 5.8epss 0.00
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
- risk 0.38cvss 5.9epss 0.00
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
- risk 0.38cvss 5.8epss 0.00
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
- risk 0.38cvss 5.9epss 0.01
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
- risk 0.38cvss 5.9epss 0.01
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
- risk 0.37cvss 6.7epss 0.00
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
- risk 0.37cvss 5.5epss 0.13
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
- risk 0.37cvss 5.3epss 0.32
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
- risk 0.37cvss 5.7epss 0.01
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
- risk 0.36cvss 5.5epss 0.00
In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
- risk 0.36cvss 5.5epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
- risk 0.36cvss 5.5epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
- risk 0.36cvss 5.5epss 0.00
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
Page 6 of 13