jetbrains
10 records · 0 with a public proof-of-concept
Disclosed vulnerabilities where the NVD names jetbrains as an affected vendor, highest CVSS first.
- HIGH 8.1CVE-2026-103493
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
youtrack
- HIGH 7.7CVE-2026-100268
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
youtrack
- MEDIUM 6.6CVE-2026-103494
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
youtrack
- MEDIUM 6.5CVE-2026-103492
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
youtrack
- MEDIUM 6.5CVE-2026-103491
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
youtrack
- MEDIUM 5.9CVE-2026-100267
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
youtrack
- MEDIUM 5.5CVE-2026-103497
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
youtrack
- MEDIUM 5.4CVE-2026-103496
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
youtrack
- MEDIUM 4.3CVE-2026-103495
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
youtrack
- MEDIUM 4.3CVE-2026-100269
In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
youtrack