Showing 25 vulnerabilities on this page for YouTrack

Signals CISA KEV Ransomware Nuclei
JetBrains vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:JetBrains YouTrack Authentication Bypass via Direct Database Access

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

CWE-306Jul 14, 2026
CVSS10.0v3.1EPSS0.329%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Stored Cross-Site Scripting via Article Titles in Digest Emails

In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

CWE-79Jul 10, 2026
CVSS3.5v3.1EPSS0.391%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack CSS Injection via Mermaid Diagram Rendering

In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

CWE-1021Jul 10, 2026
CVSS3.5v3.1EPSS0.135%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Websandbox Bridge Prototype Pollution Vulnerability

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

CWE-1321Jun 26, 2026
CVSS2.6v3.1EPSS0.188%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Improper Access Control

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

CWE-862Jun 26, 2026
CVSS4.3v3.1EPSS0.167%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Default Role Configuration Information Disclosure

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

CWE-276Jun 26, 2026
CVSS4.3v3.1EPSS0.167%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Improper Authorization in App Configurations Endpoint

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

CWE-862Jun 26, 2026
CVSS5.3v3.1EPSS0.159%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Missing Authorization for Project Settings Disclosure

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

CWE-862Jun 26, 2026
CVSS3.1v3.1EPSS0.143%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Improper Access Control via Comment Templates Endpoint

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

CWE-862Jun 26, 2026
CVSS4.3v3.1EPSS0.177%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Improper Access Control Allows Enumeration of Restricted Issues and Articles

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

CWE-639May 29, 2026
CVSS6.5v3.1EPSS0.258%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Improper Access Control

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

CWE-862May 29, 2026
CVSS6.5v3.1EPSS0.221%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Information Disclosure via fetchApp Requests

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

CWE-201May 29, 2026
CVSS3.4v3.1EPSS0.248%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Incorrect Authorization Information Disclosure Vulnerability

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

CWE-863May 29, 2026
CVSS4.3v3.1EPSS0.205%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Project Notification Templates Stored Cross-Site Scripting

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

CWE-79May 29, 2026
CVSS8.7v3.1EPSS0.206%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Sandbox Bypass Remote Code Execution

In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

CWE-1336Apr 17, 2026
CVSS7.2v3.1EPSS0.426%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Missing Authorization on App Permissions Endpoint

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

CWE-862Feb 25, 2026
CVSS8.8v3.1EPSS0.252%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Access Token Exposure in Mailbox Logs

In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

CWE-532Feb 9, 2026
CVSS6.5v3.1EPSS0.871%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit

CWE-362Nov 11, 2025
CVSS2.7v3.1EPSS0.215%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

CWE-295Nov 10, 2025
CVSS8.1v3.1EPSS0.222%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

CWE-862Nov 10, 2025
CVSS4.5v3.1EPSS0.316%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content

CWE-79Aug 20, 2025
CVSS8.7v3.1EPSS0.278%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

CWE-1021Jul 28, 2025
CVSS6.1v3.1EPSS0.26%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible

CWE-862Jul 15, 2025
CVSS7.6v3.1EPSS0.27%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

CWE-306May 20, 2025
CVSS4.3v3.1EPSS0.341%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

CWE-306May 20, 2025
CVSS7.7v3.1EPSS0.38%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX