Where
AND
-Infinity
0
Severity
6.5
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion

First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

First published (updated )
Severity
6.1
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

First published (updated )
Severity
4.8
XSS
AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N

In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

First published (updated )
Severity
6.1
EPSS
0.01%
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab

First published (updated )
Severity
5.3
EPSS
0.05%
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

First published (updated )
Severity
5.4
EPSS
0.04%
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible

First published (updated )
Severity
5.3
EPSS
0.05%
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

First published (updated )
Severity
5.3
EPSS
0.05%
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

First published (updated )
Severity
5.4
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible

First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log

First published (updated )
Severity
6.1
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads

First published (updated )
Severity
6.5
Infoleak
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations

First published (updated )
Severity
5.4
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible

First published (updated )
Severity
5.4
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible

First published (updated )
Severity
6.1
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible

First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions

First published (updated )
Severity
5.4
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible

First published (updated )
Severity
5.4
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible

First published (updated )
Severity
4.8
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible

First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible

First published (updated )
Severity
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases

First published (updated )
Severity
5.4
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible

First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API

First published (updated )
Severity
5.4
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible

First published (updated )
Severity
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203