Search Results (191 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100269 1 Jetbrains 1 Youtrack 2026-10-01 4.3 Medium
In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
CVE-2026-100268 1 Jetbrains 1 Youtrack 2026-10-01 7.7 High
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVE-2026-100267 1 Jetbrains 1 Youtrack 2026-10-01 5.9 Medium
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
CVE-2026-103489 1 Jetbrains 1 Youtrack 2026-10-01 2 Low
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
CVE-2026-103491 1 Jetbrains 1 Youtrack 2026-10-01 6.5 Medium
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVE-2026-103497 1 Jetbrains 1 Youtrack 2026-10-01 5.5 Medium
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVE-2026-103496 1 Jetbrains 1 Youtrack 2026-10-01 5.4 Medium
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVE-2026-103495 1 Jetbrains 1 Youtrack 2026-10-01 4.3 Medium
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVE-2026-103494 1 Jetbrains 1 Youtrack 2026-10-01 6.6 Medium
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVE-2026-103492 1 Jetbrains 1 Youtrack 2026-10-01 6.5 Medium
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVE-2026-103490 1 Jetbrains 1 Youtrack 2026-10-01 7.2 High
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
CVE-2026-103488 1 Jetbrains 1 Youtrack 2026-10-01 7.1 High
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
CVE-2026-86482 1 Jetbrains 1 Youtrack 2026-09-22 8.8 High
In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation
CVE-2026-75049 1 Jetbrains 1 Youtrack 2026-09-15 6.5 Medium
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
CVE-2026-75048 1 Jetbrains 1 Youtrack 2026-09-15 8.2 High
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
CVE-2026-75047 1 Jetbrains 1 Youtrack 2026-09-15 6.5 Medium
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
CVE-2026-75046 1 Jetbrains 1 Youtrack 2026-09-15 4.3 Medium
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
CVE-2026-75044 1 Jetbrains 1 Youtrack 2026-09-15 8.1 High
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
CVE-2026-75045 1 Jetbrains 1 Youtrack 2026-09-15 9.1 Critical
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVE-2026-75050 1 Jetbrains 1 Youtrack 2026-09-15 7.1 High
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters