Vulnerabilities
Vulnerable Software
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVSS Score
7.7
EPSS Score
0.003
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
CVSS Score
4.3
EPSS Score
0.003
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
CVSS Score
5.9
EPSS Score
0.004
Published
2026-09-30
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
CVSS Score
7.1
EPSS Score
0.011
Published
2026-08-17
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
CVSS Score
8.1
EPSS Score
0.004
Published
2026-08-17
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
CVSS Score
8.1
EPSS Score
0.004
Published
2026-08-17
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVSS Score
9.1
EPSS Score
0.004
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
CVSS Score
4.3
EPSS Score
0.003
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
CVSS Score
6.5
EPSS Score
0.012
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
CVSS Score
8.2
EPSS Score
0.003
Published
2026-08-17


Contact Us

Shodan ® - All rights reserved