jetbrains

10 records · 0 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names jetbrains as an affected vendor, highest CVSS first.

  1. HIGH 8.1CVE-2026-103493

    In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible

    youtrack

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.7CVE-2026-100268

    In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates

    youtrack

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.6CVE-2026-103494

    In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes

    youtrack

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-103492

    In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments

    youtrack

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.5CVE-2026-103491

    In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues

    youtrack

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 5.9CVE-2026-100267

    In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters

    youtrack

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.5CVE-2026-103497

    In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration

    youtrack

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 5.4CVE-2026-103496

    In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications

    youtrack

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 4.3CVE-2026-103495

    In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs

    youtrack

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 4.3CVE-2026-100269

    In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed

    youtrack

    AI risk analysis on Exploit-DB.ai →