Search Results (191 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100257 1 Jetbrains 1 Youtrack 2026-10-02 4.3 Medium
In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
CVE-2026-100258 1 Jetbrains 1 Youtrack 2026-10-02 4.3 Medium
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
CVE-2026-100259 1 Jetbrains 1 Youtrack 2026-10-02 4.3 Medium
In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access
CVE-2026-100260 1 Jetbrains 1 Youtrack 2026-10-02 5.3 Medium
In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
CVE-2026-100261 1 Jetbrains 1 Youtrack 2026-10-02 5.4 Medium
In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
CVE-2026-100262 1 Jetbrains 1 Youtrack 2026-10-02 7.6 High
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
CVE-2026-100263 1 Jetbrains 1 Youtrack 2026-10-02 4.7 Medium
In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
CVE-2026-100264 1 Jetbrains 1 Youtrack 2026-10-02 2.7 Low
In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
CVE-2026-100270 1 Jetbrains 1 Youtrack 2026-10-02 3.3 Low
In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations
CVE-2026-100271 1 Jetbrains 1 Youtrack 2026-10-02 2.7 Low
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects
CVE-2026-100272 1 Jetbrains 1 Youtrack 2026-10-02 4.9 Medium
In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
CVE-2026-100273 1 Jetbrains 1 Youtrack 2026-10-02 8.2 High
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
CVE-2026-100274 1 Jetbrains 1 Youtrack 2026-10-02 6.5 Medium
In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
CVE-2026-100276 1 Jetbrains 1 Youtrack 2026-10-02 5.9 Medium
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVE-2026-100277 1 Jetbrains 1 Youtrack 2026-10-02 8.9 High
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVE-2026-100278 1 Jetbrains 1 Youtrack 2026-10-02 4.9 Medium
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
CVE-2026-100279 1 Jetbrains 1 Youtrack 2026-10-02 6.5 Medium
In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
CVE-2026-100280 1 Jetbrains 1 Youtrack 2026-10-02 3.1 Low
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
CVE-2026-100275 1 Jetbrains 1 Youtrack 2026-10-02 6.9 Medium
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVE-2026-103493 1 Jetbrains 1 Youtrack 2026-10-01 8.1 High
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible