| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials |
| In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible |
| In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible |
| In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible |
| In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed |
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates |
| In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters |
| In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible |
| In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues |
| In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration |
| In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes |
| In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues |
| In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings |
| In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL |
| In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol |
| In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings |