📦

youtrack

Vendor: jetbrains

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 5 Remote Access
Total CVEs 144 Total Indexed
Avg. EPSS 0.84% Exploit Prob.
Latest CVE CVE-2026-61492 Jul 10

Security Vulnerability Index

Page 1 / 15
3.5 CVSS

In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

EPSS: 0.39%
3.5 CVSS

In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

EPSS: 0.14%
2.6 CVSS

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

EPSS: 0.18%
4.3 CVSS

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

EPSS: 0.17%
4.3 CVSS

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

EPSS: 0.17%
5.3 CVSS

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

EPSS: 0.16%
3.1 CVSS

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

EPSS: 0.14%
4.3 CVSS

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

EPSS: 0.18%
6.5 CVSS

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

EPSS: 0.25%
6.5 CVSS

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

EPSS: 0.21%