Where
-Infinity
0
Severity
5.5
SSRF
AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration

First published (updated )
Severity
5.4
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications

First published (updated )
Severity
8.1
XSS
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs

First published (updated )
Severity
6.6
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments

First published (updated )
Severity
7.2
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues

First published (updated )
Severity
5.4
XSS
AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N

In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible

First published (updated )
Severity
7.1
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues

First published (updated )
Severity
4.3
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible

First published (updated )
Severity
4.9
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments

First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature

First published (updated )
Severity
6.5
SSRF
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials

First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action

First published (updated )
Severity
6.9
XSS
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N

In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template

First published (updated )
Severity
9.8
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution

First published (updated )
Severity
4.9
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues

First published (updated )
Severity
3.3
AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations

First published (updated )
Severity
2.7
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects

First published (updated )
Severity
7.7
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates

First published (updated )
Severity
5.9
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed

First published (updated )
Severity
2.7
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host

First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible

First published (updated )
Severity
7.6
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates

First published (updated )
Severity
5.4
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203