Where
-Infinity
0

JetBrains YouTrackIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.14843…

Risk 87
Severity
10
First published (updated )

JetBrains YouTrackXSS

Risk 38
Severity
6.1
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

Risk 19
Severity
3.5
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollut…

Risk 86
Severity
9.8
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and …

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JetBrains YouTrackIn JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint …

Risk 43
Severity
7.5
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile …

Risk 27
Severity
5.3
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private dat…

Risk 43
Severity
7.5
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

Risk 27
Severity
5.3
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to mo…

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JetBrains YouTrackIn JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted …

Risk 38
Severity
6.5
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

Risk 43
Severity
7.5
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pa…

Risk 22
Severity
4.3
First published (updated )

JetBrains YouTrackXSS

Risk 61
Severity
8.7
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

Risk 66
Severity
7.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JetBrains YouTrackIn JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions en…

Risk 56
Severity
8.8
EPSS
0.00%
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

Risk 27
Severity
6.5
EPSS
0.00%
First published (updated )

JetBrains YouTrackRace Condition

Risk 20
Severity
3.7
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosur…

Risk 60
Severity
8.1
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cl…

Risk 19
Severity
5.3
EPSS
0.00%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JetBrains YouTrackIn JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission …

Risk 31
Severity
7.7
EPSS
0.00%
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpde…

Risk 51
Severity
7.8
EPSS
0.05%
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs

Risk 23
Severity
5.5
EPSS
0.04%
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in R…

Risk 38
Severity
6.5
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycod…

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JetBrains YouTrackIn JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype poll…

Risk 40
Severity
6.5
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names d…

Risk 27
Severity
5.3
First published (updated )

JetBrains YouTrackPath Traversal

Risk 86
Severity
9.8
First published (updated )

JetBrains YouTrackIn JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via …

Risk 37
Severity
6.5
First published (updated )

JetBrains YouTrackXSS

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203