Vulnerabilities
Vulnerable Software
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVSS Score
4.3
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVSS Score
5.4
EPSS Score
0.001
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVSS Score
5.5
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVSS Score
6.5
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVSS Score
6.5
EPSS Score
0.007
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVSS Score
8.1
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVSS Score
6.6
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVSS Score
6.9
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVSS Score
5.9
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVSS Score
8.9
EPSS Score
0.003
Published
2026-09-30


Contact Us

Shodan ® - All rights reserved