| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed |
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates |
| In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters |
| In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible |
| In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues |
| In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration |
| In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes |
| In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues |
| In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation |
| In JetBrains YouTrack before 2026.1.13903,
2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint |
| In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible |
| In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint |
| In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint |
| In JetBrains YouTrack before 2025.3.156085,
2026.1.13914,
2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint |
| In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature |
| In JetBrains YouTrack before 2026.1.13901,
2026.2.17950 doS attack was possible via crafted type parameters |