Vulnerabilities
Vulnerable Software
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
CVSS Score
8.1
EPSS Score
0.002
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
CVSS Score
6.5
EPSS Score
0.009
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
CVSS Score
8.2
EPSS Score
0.002
Published
2026-08-17
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
CVSS Score
10.0
EPSS Score
0.003
Published
2026-07-14
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
CVSS Score
3.5
EPSS Score
0.007
Published
2026-07-10
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
CVSS Score
3.5
EPSS Score
0.002
Published
2026-07-10
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
CVSS Score
5.3
EPSS Score
0.003
Published
2026-06-26
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
CVSS Score
4.3
EPSS Score
0.003
Published
2026-06-26
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
CVSS Score
4.3
EPSS Score
0.003
Published
2026-06-26
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
CVSS Score
2.6
EPSS Score
0.003
Published
2026-06-26


Contact Us

Shodan ® - All rights reserved